CVE-2025-37793: ASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe()
Published May 1, 2025
·Updated
ASoC: Intel: avs: Fix null-ptr-deref in avscomponentprobe()
Affected Software
8 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=6.6<6.6.88
Linux Linux kernel>=6.7<6.12.25
Linux Linux kernel>=6.13<6.14.4
Linux Linux kernel=6.15-rc1
Linux Linux kernel=6.15-rc2
Microsoft azl3 kernel 6.6.85.1-4
Microsoft azl3 kernel 6.6.92.2-1
Remediation
Event History
May 1, 2025
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 11, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-37793?
CVE-2025-37793 has been classified as a medium severity vulnerability due to the potential for null pointer dereference.
2
How do I fix CVE-2025-37793?
To fix CVE-2025-37793, ensure you update to the latest version of the Linux kernel where the vulnerability has been patched.
3
What systems are affected by CVE-2025-37793?
CVE-2025-37793 affects the Linux kernel specifically in its audio component subsystem.
4
What are the consequences of CVE-2025-37793?
The consequence of CVE-2025-37793 can lead to application crashes or unexpected behavior if the affected code is executed.
5
Is there a workaround for CVE-2025-37793?
Currently, there are no documented workarounds for CVE-2025-37793, and applying the patch is recommended.