PT-2025-29028 · Linux+2 · Linux Kernel+2

Published

2025-05-30

·

Updated

2025-11-18

·

CVE-2025-38308

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains an issue in the Advanced SoC (ASoC) Intel audio subsystem where a null pointer dereference could occur during hardware initialization. The avs dai find path template() search result is not verified before use. Because the 'template' is already known when avs hw constraints init() is called, the search is dropped.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-09055
CVE-2025-38308

Affected Products

Astra Linux
Intel Audio Subsystem
Linux Kernel