CVE-2025-40097

ALSA: hda: Fix missing pointer check in hda_component_manager_init function

References

Notes

 carnil> Introduced in ae7abe36e352 ("ALSA: hda/realtek: Add CS35L41 support for
 carnil> Thinkpad laptops"). Vulnerable versions: 5.17.

Bugs

Status

Branch Status
upstream released (6.18-rc2) [1cf11d80db5df805b538c942269e05a65bcaf5bc]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable released (6.17.5) [47d1b9ca923b55c3f407788f1f15b04957e0e027]
6.12-upstream-stable released (6.12.59) [218a8504e62fc2c8a1fd12523346b7a2b9bd2474]
6.6-upstream-stable needed
6.1-upstream-stable needed
5.10-upstream-stable N/A "Vulnerable code not present"
sid released (6.17.6-1)
6.12-trixie-security released (6.12.63-1)
6.1-bookworm-security needed
5.10-bullseye-security N/A "Vulnerable code not present"