PT-2025-44388 · Linux+3 · Linux Kernel+3
Published
2025-10-11
·
Updated
2026-04-20
·
CVE-2025-40098
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel's ALSA subsystem, specifically within the
cs35l41 get acpi mute state() function. The issue involves a potential NULL pointer dereference because the return value of the acpi evaluate dsm() function is used without a prior NULL check, despite being typically checked for in this function. The acpi evaluate dsm() function can return NULL if acpi evaluate object() does not return ACPI SUCCESS, which can lead to a crash. This was discovered by the Linux Verification Center (linuxtesting.org) using SVACE.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Ubuntu