CVE-2025-39930

MEDIUM

Linux Kernel 6.14-6.14.2 - Use-After-Free in ASoC simple-card-utils

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai() commit 419d1918105e ("ASoC: simple-card-utils: use __free(device_node) for device node") uses __free(device_node) for dlc->of_node, but we need to keep it while driver is in use. Don't use __free(device_node) in graph_util_parse_dai().

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 13.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (19)
linux/Kernel < 6.6.135linux
linux/Kernel 6.13.0 - 6.14.2linux
linux/Kernel 6.14.0 - 6.14.2linux
linux/Kernel 6.7.0 - 6.12.82linux
Linux/Linux < 6.14
Linux/Linux 142a386a805809e21361976d566392bcd07870b8
Linux/Linux 142a386a805809e21361976d566392bcd07870b8 - 16a49e3fda339aa552cde7f2cdbb25b91426cb8a
Linux/Linux 419d1918105e5d9926ab02f1f834bb416dc76f65 - 232a32e8a7e9be8a2ee238df9b5304eed2f4e195
Linux/Linux 419d1918105e5d9926ab02f1f834bb416dc76f65 - de74ec718e0788e1998eb7289ad07970e27cae27
Linux/Linux 6.12.78 - 6.12.82
... and 9 more
Published Apr 18, 2025
Tracked Since Feb 18, 2026