CVE-2025-21847
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Mar 12, 2025
Updated: Mar 13, 2025
CWE ID 476
Summary
CVE-2025-21847 is a Linux kernel vulnerability affecting the Advanced SoC (ASoC) subsystem. It involves a nullity check issue in the 'sof_ipc_msg_data()' function. The function incorrectly assumes that 'sps->cstream' is not NULL when 'sps->stream' is NULL. This assumption can lead to a NULL pointer dereference, potentially resulting in system crashes or even allowing attackers to exploit the vulnerability for malicious purposes. The issue has been resolved in the latest kernel updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX