CVE-2025-68205

Linux Kernel 6.17-6.17.9 - Denial of Service via ALSA HDMI Driver NULL Dereference

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/hdmi: Fix breakage at probing nvhdmi-mcp driver After restructuring and splitting the HDMI codec driver code, each HDMI codec driver contains the own build_controls and build_pcms ops. A copy-n-paste error put the wrong entries for nvhdmi-mcp driver; both build_controls and build_pcms are swapped. Unfortunately both callbacks have the very same form, and the compiler didn't complain it, either. This resulted in a NULL dereference because the PCM instance hasn't been initialized at calling the build_controls callback. Fix it by passing the proper entries.

Scores

EPSS 0.0003
EPSS Percentile 8.0%

Details

Status published
Products (7)
linux/Kernel 6.17.0 - 6.17.9linux
Linux/Linux < 6.17
Linux/Linux 6.17
Linux/Linux 6.17.9 - 6.17.*
Linux/Linux 6.18
Linux/Linux ad781b550f9a8829e3dae4bd3d18c4a126a53d04 - 82420bd4e17bdaba8453fbf9e10c58c9ed0c9727
Linux/Linux ad781b550f9a8829e3dae4bd3d18c4a126a53d04 - d2aed6fac1148528181affb781aa683d6569042b
Published Dec 16, 2025
Tracked Since Feb 18, 2026