CVE-2025-38299 (GCVE-0-2025-38299)
Vulnerability from cvelistv5
Published
2025-07-10 07:42
Modified
2025-07-28 04:17
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY() ETDM2_IN_BE and ETDM1_OUT_BE are defined as COMP_EMPTY(), in the case the codec dai_name will be null. Avoid a crash if the device tree is not assigning a codec to these links. [ 1.179936] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [ 1.181065] Mem abort info: [ 1.181420] ESR = 0x0000000096000004 [ 1.181892] EC = 0x25: DABT (current EL), IL = 32 bits [ 1.182576] SET = 0, FnV = 0 [ 1.182964] EA = 0, S1PTW = 0 [ 1.183367] FSC = 0x04: level 0 translation fault [ 1.183983] Data abort info: [ 1.184406] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 1.185097] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 1.185766] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 1.186439] [0000000000000000] user address but active_mm is swapper [ 1.187239] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP [ 1.188029] Modules linked in: [ 1.188420] CPU: 7 UID: 0 PID: 70 Comm: kworker/u32:1 Not tainted 6.14.0-rc4-next-20250226+ #85 [ 1.189515] Hardware name: Radxa NIO 12L (DT) [ 1.190065] Workqueue: events_unbound deferred_probe_work_func [ 1.190808] pstate: 40400009 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 1.191683] pc : __pi_strcmp+0x24/0x140 [ 1.192170] lr : mt8195_mt6359_soc_card_probe+0x224/0x7b0 [ 1.192854] sp : ffff800083473970 [ 1.193271] x29: ffff800083473a10 x28: 0000000000001008 x27: 0000000000000002 [ 1.194168] x26: ffff800082408960 x25: ffff800082417db0 x24: ffff800082417d88 [ 1.195065] x23: 000000000000001e x22: ffff800082dbf480 x21: ffff800082dc07b8 [ 1.195961] x20: 0000000000000000 x19: 0000000000000013 x18: 00000000ffffffff [ 1.196858] x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000006 [ 1.197755] x14: ffff800082407af0 x13: 6e6f69737265766e x12: 692d6b636f6c6374 [ 1.198651] x11: 0000000000000002 x10: ffff80008240b920 x9 : 0000000000000018 [ 1.199547] x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000 [ 1.200443] x5 : 0000000000000000 x4 : 8080808080000000 x3 : 303933383978616d [ 1.201339] x2 : 0000000000000000 x1 : ffff80008240b920 x0 : 0000000000000000 [ 1.202236] Call trace: [ 1.202545] __pi_strcmp+0x24/0x140 (P) [ 1.203029] mtk_soundcard_common_probe+0x3bc/0x5b8 [ 1.203644] platform_probe+0x70/0xe8 [ 1.204106] really_probe+0xc8/0x3a0 [ 1.204556] __driver_probe_device+0x84/0x160 [ 1.205104] driver_probe_device+0x44/0x130 [ 1.205630] __device_attach_driver+0xc4/0x170 [ 1.206189] bus_for_each_drv+0x8c/0xf8 [ 1.206672] __device_attach+0xa8/0x1c8 [ 1.207155] device_initial_probe+0x1c/0x30 [ 1.207681] bus_probe_device+0xb0/0xc0 [ 1.208165] deferred_probe_work_func+0xa4/0x100 [ 1.208747] process_one_work+0x158/0x3e0 [ 1.209254] worker_thread+0x2c4/0x3e8 [ 1.209727] kthread+0x134/0x1f0 [ 1.210136] ret_from_fork+0x10/0x20 [ 1.210589] Code: 54000401 b50002c6 d503201f f86a6803 (f8408402) [ 1.211355] ---[ end trace 0000000000000000 ]---
Impacted products
Vendor Product Version
Linux Linux Version: e70b8dd26711704b1ff1f1b4eb3d048ba69e29da
Version: e70b8dd26711704b1ff1f1b4eb3d048ba69e29da
Version: e70b8dd26711704b1ff1f1b4eb3d048ba69e29da
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "sound/soc/mediatek/mt8195/mt8195-mt6359.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "87dbfe2b392df9621f6e522e5fa6fb8849ca92ab",
              "status": "affected",
              "version": "e70b8dd26711704b1ff1f1b4eb3d048ba69e29da",
              "versionType": "git"
            },
            {
              "lessThan": "183e7329d41d7a8e298f48b6b0eb81102a8654de",
              "status": "affected",
              "version": "e70b8dd26711704b1ff1f1b4eb3d048ba69e29da",
              "versionType": "git"
            },
            {
              "lessThan": "7af317f7faaab09d5a78f24605057d11f5955115",
              "status": "affected",
              "version": "e70b8dd26711704b1ff1f1b4eb3d048ba69e29da",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "sound/soc/mediatek/mt8195/mt8195-mt6359.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "lessThan": "6.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.34",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.15.*",
              "status": "unaffected",
              "version": "6.15.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.16",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.34",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15.3",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()\n\nETDM2_IN_BE and ETDM1_OUT_BE are defined as COMP_EMPTY(),\nin the case the codec dai_name will be null.\n\nAvoid a crash if the device tree is not assigning a codec\nto these links.\n\n[    1.179936] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[    1.181065] Mem abort info:\n[    1.181420]   ESR = 0x0000000096000004\n[    1.181892]   EC = 0x25: DABT (current EL), IL = 32 bits\n[    1.182576]   SET = 0, FnV = 0\n[    1.182964]   EA = 0, S1PTW = 0\n[    1.183367]   FSC = 0x04: level 0 translation fault\n[    1.183983] Data abort info:\n[    1.184406]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[    1.185097]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[    1.185766]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[    1.186439] [0000000000000000] user address but active_mm is swapper\n[    1.187239] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[    1.188029] Modules linked in:\n[    1.188420] CPU: 7 UID: 0 PID: 70 Comm: kworker/u32:1 Not tainted 6.14.0-rc4-next-20250226+ #85\n[    1.189515] Hardware name: Radxa NIO 12L (DT)\n[    1.190065] Workqueue: events_unbound deferred_probe_work_func\n[    1.190808] pstate: 40400009 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[    1.191683] pc : __pi_strcmp+0x24/0x140\n[    1.192170] lr : mt8195_mt6359_soc_card_probe+0x224/0x7b0\n[    1.192854] sp : ffff800083473970\n[    1.193271] x29: ffff800083473a10 x28: 0000000000001008 x27: 0000000000000002\n[    1.194168] x26: ffff800082408960 x25: ffff800082417db0 x24: ffff800082417d88\n[    1.195065] x23: 000000000000001e x22: ffff800082dbf480 x21: ffff800082dc07b8\n[    1.195961] x20: 0000000000000000 x19: 0000000000000013 x18: 00000000ffffffff\n[    1.196858] x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000006\n[    1.197755] x14: ffff800082407af0 x13: 6e6f69737265766e x12: 692d6b636f6c6374\n[    1.198651] x11: 0000000000000002 x10: ffff80008240b920 x9 : 0000000000000018\n[    1.199547] x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000\n[    1.200443] x5 : 0000000000000000 x4 : 8080808080000000 x3 : 303933383978616d\n[    1.201339] x2 : 0000000000000000 x1 : ffff80008240b920 x0 : 0000000000000000\n[    1.202236] Call trace:\n[    1.202545]  __pi_strcmp+0x24/0x140 (P)\n[    1.203029]  mtk_soundcard_common_probe+0x3bc/0x5b8\n[    1.203644]  platform_probe+0x70/0xe8\n[    1.204106]  really_probe+0xc8/0x3a0\n[    1.204556]  __driver_probe_device+0x84/0x160\n[    1.205104]  driver_probe_device+0x44/0x130\n[    1.205630]  __device_attach_driver+0xc4/0x170\n[    1.206189]  bus_for_each_drv+0x8c/0xf8\n[    1.206672]  __device_attach+0xa8/0x1c8\n[    1.207155]  device_initial_probe+0x1c/0x30\n[    1.207681]  bus_probe_device+0xb0/0xc0\n[    1.208165]  deferred_probe_work_func+0xa4/0x100\n[    1.208747]  process_one_work+0x158/0x3e0\n[    1.209254]  worker_thread+0x2c4/0x3e8\n[    1.209727]  kthread+0x134/0x1f0\n[    1.210136]  ret_from_fork+0x10/0x20\n[    1.210589] Code: 54000401 b50002c6 d503201f f86a6803 (f8408402)\n[    1.211355] ---[ end trace 0000000000000000 ]---"
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-07-28T04:17:53.157Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/87dbfe2b392df9621f6e522e5fa6fb8849ca92ab"
        },
        {
          "url": "https://git.kernel.org/stable/c/183e7329d41d7a8e298f48b6b0eb81102a8654de"
        },
        {
          "url": "https://git.kernel.org/stable/c/7af317f7faaab09d5a78f24605057d11f5955115"
        }
      ],
      "title": "ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-38299",
    "datePublished": "2025-07-10T07:42:12.216Z",
    "dateReserved": "2025-04-16T04:51:24.002Z",
    "dateUpdated": "2025-07-28T04:17:53.157Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "nvd": "{\"cve\":{\"id\":\"CVE-2025-38299\",\"sourceIdentifier\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\",\"published\":\"2025-07-10T08:15:28.623\",\"lastModified\":\"2025-07-10T13:17:30.017\",\"vulnStatus\":\"Awaiting Analysis\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"In the Linux kernel, the following vulnerability has been resolved:\\n\\nASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()\\n\\nETDM2_IN_BE and ETDM1_OUT_BE are defined as COMP_EMPTY(),\\nin the case the codec dai_name will be null.\\n\\nAvoid a crash if the device tree is not assigning a codec\\nto these links.\\n\\n[    1.179936] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\\n[    1.181065] Mem abort info:\\n[    1.181420]   ESR = 0x0000000096000004\\n[    1.181892]   EC = 0x25: DABT (current EL), IL = 32 bits\\n[    1.182576]   SET = 0, FnV = 0\\n[    1.182964]   EA = 0, S1PTW = 0\\n[    1.183367]   FSC = 0x04: level 0 translation fault\\n[    1.183983] Data abort info:\\n[    1.184406]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\\n[    1.185097]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\\n[    1.185766]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\\n[    1.186439] [0000000000000000] user address but active_mm is swapper\\n[    1.187239] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\\n[    1.188029] Modules linked in:\\n[    1.188420] CPU: 7 UID: 0 PID: 70 Comm: kworker/u32:1 Not tainted 6.14.0-rc4-next-20250226+ #85\\n[    1.189515] Hardware name: Radxa NIO 12L (DT)\\n[    1.190065] Workqueue: events_unbound deferred_probe_work_func\\n[    1.190808] pstate: 40400009 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\\n[    1.191683] pc : __pi_strcmp+0x24/0x140\\n[    1.192170] lr : mt8195_mt6359_soc_card_probe+0x224/0x7b0\\n[    1.192854] sp : ffff800083473970\\n[    1.193271] x29: ffff800083473a10 x28: 0000000000001008 x27: 0000000000000002\\n[    1.194168] x26: ffff800082408960 x25: ffff800082417db0 x24: ffff800082417d88\\n[    1.195065] x23: 000000000000001e x22: ffff800082dbf480 x21: ffff800082dc07b8\\n[    1.195961] x20: 0000000000000000 x19: 0000000000000013 x18: 00000000ffffffff\\n[    1.196858] x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000006\\n[    1.197755] x14: ffff800082407af0 x13: 6e6f69737265766e x12: 692d6b636f6c6374\\n[    1.198651] x11: 0000000000000002 x10: ffff80008240b920 x9 : 0000000000000018\\n[    1.199547] x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000\\n[    1.200443] x5 : 0000000000000000 x4 : 8080808080000000 x3 : 303933383978616d\\n[    1.201339] x2 : 0000000000000000 x1 : ffff80008240b920 x0 : 0000000000000000\\n[    1.202236] Call trace:\\n[    1.202545]  __pi_strcmp+0x24/0x140 (P)\\n[    1.203029]  mtk_soundcard_common_probe+0x3bc/0x5b8\\n[    1.203644]  platform_probe+0x70/0xe8\\n[    1.204106]  really_probe+0xc8/0x3a0\\n[    1.204556]  __driver_probe_device+0x84/0x160\\n[    1.205104]  driver_probe_device+0x44/0x130\\n[    1.205630]  __device_attach_driver+0xc4/0x170\\n[    1.206189]  bus_for_each_drv+0x8c/0xf8\\n[    1.206672]  __device_attach+0xa8/0x1c8\\n[    1.207155]  device_initial_probe+0x1c/0x30\\n[    1.207681]  bus_probe_device+0xb0/0xc0\\n[    1.208165]  deferred_probe_work_func+0xa4/0x100\\n[    1.208747]  process_one_work+0x158/0x3e0\\n[    1.209254]  worker_thread+0x2c4/0x3e8\\n[    1.209727]  kthread+0x134/0x1f0\\n[    1.210136]  ret_from_fork+0x10/0x20\\n[    1.210589] Code: 54000401 b50002c6 d503201f f86a6803 (f8408402)\\n[    1.211355] ---[ end trace 0000000000000000 ]---\"},{\"lang\":\"es\",\"value\":\"En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ASoC: mediatek: mt8195: Establecer ETDM1/2 IN/OUT como COMP_DUMMY(). ETDM2_IN_BE y ETDM1_OUT_BE se definen como COMP_EMPTY(); en ese caso, el c\u00f3dec dai_name ser\u00e1 nulo. Se evita un bloqueo si el \u00e1rbol de dispositivos no asigna un c\u00f3dec a estos enlaces. [ 1.179936] No se puede manejar la desreferencia del puntero NULL del n\u00facleo en la direcci\u00f3n virtual 0000000000000000 [ 1.181065] Mem abort info: [ 1.181420] ESR = 0x0000000096000004 [ 1.181892] EC = 0x25: DABT (current EL), IL = 32 bits [ 1.182576] SET = 0, FnV = 0 [ 1.182964] EA = 0, S1PTW = 0 [ 1.183367] FSC = 0x04: level 0 translation fault [ 1.183983] Data abort info: [ 1.184406] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 1.185097] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 1.185766] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 1.186439] [0000000000000000] user address but active_mm is swapper [ 1.187239] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP [ 1.188029] Modules linked in: [ 1.188420] CPU: 7 UID: 0 PID: 70 Comm: kworker/u32:1 Not tainted 6.14.0-rc4-next-20250226+ #85 [ 1.189515] Hardware name: Radxa NIO 12L (DT) [ 1.190065] Workqueue: events_unbound deferred_probe_work_func [ 1.190808] pstate: 40400009 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 1.191683] pc : __pi_strcmp+0x24/0x140 [ 1.192170] lr : mt8195_mt6359_soc_card_probe+0x224/0x7b0 [ 1.192854] sp : ffff800083473970 [ 1.193271] x29: ffff800083473a10 x28: 0000000000001008 x27: 0000000000000002 [ 1.194168] x26: ffff800082408960 x25: ffff800082417db0 x24: ffff800082417d88 [ 1.195065] x23: 000000000000001e x22: ffff800082dbf480 x21: ffff800082dc07b8 [ 1.195961] x20: 0000000000000000 x19: 0000000000000013 x18: 00000000ffffffff [ 1.196858] x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000006 [ 1.197755] x14: ffff800082407af0 x13: 6e6f69737265766e x12: 692d6b636f6c6374 [ 1.198651] x11: 0000000000000002 x10: ffff80008240b920 x9 : 0000000000000018 [ 1.199547] x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000 [ 1.200443] x5 : 0000000000000000 x4 : 8080808080000000 x3 : 303933383978616d [ 1.201339] x2 : 0000000000000000 x1 : ffff80008240b920 x0 : 0000000000000000 [ 1.202236] Call trace: [ 1.202545] __pi_strcmp+0x24/0x140 (P) [ 1.203029] mtk_soundcard_common_probe+0x3bc/0x5b8 [ 1.203644] platform_probe+0x70/0xe8 [ 1.204106] really_probe+0xc8/0x3a0 [ 1.204556] __driver_probe_device+0x84/0x160 [ 1.205104] driver_probe_device+0x44/0x130 [ 1.205630] __device_attach_driver+0xc4/0x170 [ 1.206189] bus_for_each_drv+0x8c/0xf8 [ 1.206672] __device_attach+0xa8/0x1c8 [ 1.207155] device_initial_probe+0x1c/0x30 [ 1.207681] bus_probe_device+0xb0/0xc0 [ 1.208165] deferred_probe_work_func+0xa4/0x100 [ 1.208747] process_one_work+0x158/0x3e0 [ 1.209254] worker_thread+0x2c4/0x3e8 [ 1.209727] kthread+0x134/0x1f0 [ 1.210136] ret_from_fork+0x10/0x20 [ 1.210589] Code: 54000401 b50002c6 d503201f f86a6803 (f8408402) [ 1.211355] ---[ fin de seguimiento 0000000000000000 ]---\"}],\"metrics\":{},\"references\":[{\"url\":\"https://git.kernel.org/stable/c/183e7329d41d7a8e298f48b6b0eb81102a8654de\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/7af317f7faaab09d5a78f24605057d11f5955115\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"},{\"url\":\"https://git.kernel.org/stable/c/87dbfe2b392df9621f6e522e5fa6fb8849ca92ab\",\"source\":\"416baaa9-dc9f-4396-8d5f-8c081fb06d67\"}]}}"
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…