cbcvebase.
CVE-2025-68345
published 2025-12-24

CVE-2025-68345: In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi() The…

PriorityP421high7.2
EPSS
0.21%
11.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi() The acpi_get_first_physical_node() function can return NULL, in which case the get_device() function also returns NULL, but this value is then dereferenced without checking,so add a check to prevent a crash. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 7b2f3eb492dac7665c75df067e4d8e4869589f4a < e63f9c81ca28b06eeeac3630faddc50717897351e63f9c81ca28b06eeeac3630faddc50717897351
linuxlinux>= 7b2f3eb492dac7665c75df067e4d8e4869589f4a < 7a35a505d76a4b6cd426b59ff2d800d0394cc5d37a35a505d76a4b6cd426b59ff2d800d0394cc5d3
linuxlinux>= 7b2f3eb492dac7665c75df067e4d8e4869589f4a < e6ba921b17797ccc545d80e0dbccb5fab91c248ce6ba921b17797ccc545d80e0dbccb5fab91c248c
linuxlinux>= 7b2f3eb492dac7665c75df067e4d8e4869589f4a < c28946b7409b7b68fb0481ec738c8b04578b11c6c28946b7409b7b68fb0481ec738c8b04578b11c6
linuxlinux>= 7b2f3eb492dac7665c75df067e4d8e4869589f4a < 343fa9800cf9870ec681e21f0a6f2157b74ae520343fa9800cf9870ec681e21f0a6f2157b74ae520
linuxlinux>= 7b2f3eb492dac7665c75df067e4d8e4869589f4a < c34b04cc6178f33c08331568c7fd25c5b9a39f66c34b04cc6178f33c08331568c7fd25c5b9a39f66
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.17.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.