PT-2025-37223 · Linux+3 · Linux Kernel+3
Syzkaller
·
Published
2025-08-21
·
Updated
2026-04-08
·
CVE-2025-39765
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.15.8
Description:
A flaw exists in the Linux kernel's ALSA timer functionality. Specifically, within the
snd utimer create() function, a potential issue arises if the kasprintf() function returns NULL. This can lead to a call to snd utimer put id(), which subsequently attempts to free an unallocated ID (0) using ida free(). This condition was reported by the syzkaller fuzzer.Recommendations:
Update to Linux kernel version 6.15.8 or later.
Exploit
Fix
NULL Pointer Dereference
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse