CVE-2025-40344 — Expired Pointer Dereference in Linux
Severity
5.2MEDIUM
No vectorEPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: avs: Disable periods-elapsed work when closing PCM
avs_dai_fe_shutdown() handles the shutdown procedure for HOST HDAudio
stream while period-elapsed work services its IRQs. As the former
frees the DAI's private context, these two operations shall be
synchronized to avoid slab-use-after-free or worse errors.
Affected Packages5 packages
▶CVEListV5linux/linux0dbb186c3510cad4e9f443e801bf2e6ab5770c00 — ca6d2b7aca778afbf8c0c4b330d10cb228c14052+4