CVE-2025-21870

ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers

References

Notes

 carnil> Introduced in a150345aa758 ("ASoC: SOF: ipc4-topology: add SoundWire/ALH
 carnil> aggregation support"). Vulnerable versions: 6.0.

Bugs

Status

Branch Status
upstream released (6.14-rc4) [6fd60136d256b3b948333ebdb3835f41a95ab7ef]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.13-upstream-stable released (6.13.5) [93c6c2e5801aab09ef1ef99f248f3cd323c3f152]
6.12-upstream-stable released (6.12.17) [87c8768a96092ce75cd47fe076db5080db7ac515]
6.6-upstream-stable needed
6.1-upstream-stable needed
5.10-upstream-stable N/A "Vulnerable code not present"
sid released (6.12.17-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security needed
5.10-bullseye-security N/A "Vulnerable code not present"