CVE-2025-68345

Advisory lineage Upstream: 0 Downstream: 38
Deferred
Published: 24 Dec 2025, 10:32
Last modified:11 May 2026, 21:51

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
0.02% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Dec 2025, 10:32
Published
Vulnerability first disclosed
11 May 2026, 21:51
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi() The acpi_get_first_physical_node() function can return NULL, in which case the get_device() function also returns NULL, but this value is then dereferenced without checking,so add a check to prevent a crash. Found by Linux Verification Center (linuxtesting.org) with SVACE.

EPSS Trends

Current EPSS score: 0.02% Percentile: 6%

Affected Systems

  • linuxlinux

    ≥ 7b2f3eb492dac7665c75df067e4d8e4869589f4a, < e63f9c81ca28b06eeeac3630faddc50717897351 | ≥ 7b2f3eb492dac7665c75df067e4d8e4869589f4a, < 7a35a505d76a4b6cd426b59ff2d800d0394cc5d3 | ≥ 7b2f3eb492dac7665c75df067e4d8e4869589f4a, < e6ba921b17797ccc545d80e0dbccb5fab91c248c | ≥ 7b2f3eb492dac7665c75df067e4d8e4869589f4a, < c28946b7409b7b68fb0481ec738c8b04578b11c6 | ≥ 7b2f3eb492dac7665c75df067e4d8e4869589f4a, < 343fa9800cf9870ec681e21f0a6f2157b74ae520 | ≥ 7b2f3eb492dac7665c75df067e4d8e4869589f4a, < c34b04cc6178f33c08331568c7fd25c5b9a39f66 | 5.17

References (6)