CVE-2025-21847

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 12, 2025
Updated: Mar 13, 2025
CWE ID 476

Summary

CVE-2025-21847 is a Linux kernel vulnerability affecting the Advanced SoC (ASoC) subsystem. It involves a nullity check issue in the 'sof_ipc_msg_data()' function. The function incorrectly assumes that 'sps->cstream' is not NULL when 'sps->stream' is NULL. This assumption can lead to a NULL pointer dereference, potentially resulting in system crashes or even allowing attackers to exploit the vulnerability for malicious purposes. The issue has been resolved in the latest kernel updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share