cbcvebase.
CVE-2025-40338
published 2025-12-09

CVE-2025-40338: In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Do not share the name pointer between components By sharing 'name'…

PriorityP424high7
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Do not share the name pointer between components By sharing 'name' directly, tearing down components may lead to use-after-free errors. Duplicate the name to avoid that. At the same time, update the order of operations - since commit cee28113db17 ("ASoC: dmaengine_pcm: Allow passing component name via config") the framework does not override component->name if set before invoking the initializer.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= f1b3b320bd6519b16e3480f74f2926d106e3bcba < 128bf29c992988f8b4f3829227339908fde5ec86128bf29c992988f8b4f3829227339908fde5ec86
linuxlinux>= f1b3b320bd6519b16e3480f74f2926d106e3bcba < 4dee5c1cc439b0d5ef87f741518268ad6a95b23d4dee5c1cc439b0d5ef87f741518268ad6a95b23d
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.19.0 < 6.17.86.17.8
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

vendor_msrc7.0HIGH
vendor_redhat5.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.