Vulnerability Bulletins

CVE-2025-40162

   
Affected software AMD
 
In the Linux kernel, the following vulnerability has been resolved:

ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() fails

devm_kasprintf() may return NULL on memory allocation failure,
but the debug message prints cpus->dai_name before checking it.
Move the dev_dbg() call after the NULL check to prevent potential
NULL pointer dereference.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2025-40162