CVE-2026-43137

MEDIUM

Linux - NULL Pointer Dereference in ASoC SOF Intel HDA Widget Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Fix NULL pointer dereference If there's a mismatch between the DAI links in the machine driver and the topology, it is possible that the playback/capture widget is not set, especially in the case of loopback capture for echo reference where we use the dummy DAI link. Return the error when the widget is not set to avoid a null pointer dereference like below when the topology is broken. RIP: 0010:hda_dai_get_ops.isra.0+0x14/0xa0 [snd_sof_intel_hda_common]

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (17)
Linux/Linux < 5.16
Linux/Linux 0acb48dd31e39b617bb12ca546b4fecd6ccb2972 - 10411f1f2c76be67103b1f95822ff629aa25e2aa
Linux/Linux 0acb48dd31e39b617bb12ca546b4fecd6ccb2972 - 16c589567a956d46a7c1363af3f64de3d420af20
Linux/Linux 0acb48dd31e39b617bb12ca546b4fecd6ccb2972 - 42068f7dd42b559c4eeae645e1455ff36518866a
Linux/Linux 0acb48dd31e39b617bb12ca546b4fecd6ccb2972 - 7750d78b4014902bc0ac03d4bb30faa076a913ab
Linux/Linux 0acb48dd31e39b617bb12ca546b4fecd6ccb2972 - a1d4f3d3c0dc86527da6a19f6901a6a48375500d
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 10411f1f2c76be67103b1f95822ff629aa25e2aa
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 16c589567a956d46a7c1363af3f64de3d420af20
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 42068f7dd42b559c4eeae645e1455ff36518866a
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 7750d78b4014902bc0ac03d4bb30faa076a913ab
... and 7 more
Published May 06, 2026
Tracked Since May 06, 2026