CVE-2025-37889
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-37889 was discovered and published on May 9, 2025, affecting the Linux kernel's ASoC (ALSA System on Chip) audio subsystem. The vulnerability involves inconsistent handling of platform_max values in the volume control implementation (NVD).

Technical details

The vulnerability stems from inconsistent interpretation of the platform_max parameter in the ASoC subsystem. The issue arose after reverting commit 9bdd10d57a88 which had changed the interpretation of platform_max from a control value to a register value. While this change was initially technically correct as snd_soc_limit_volume() used the register interpretation, most other usages treated platform_max as a control value. The commit fb9ad24485087 later updated snd_soc_limit_volume() to use the control interpretation, but missed updating snd_soc_put_volsw() and snd_soc_info_volsw_range() (NVD).

Impact

The inconsistent interpretation of platform_max values could lead to incorrect volume control behavior in affected Linux systems. Since volume limiting is typically handled by the machine driver, using the internal codec representation instead of the customer-facing representation could result in unexpected audio volume levels (NVD).

Exploitability

The vulnerability has been assigned a CVSS v3.1 base score of 5.5, indicating moderate severity with local access required (RedHat).

Mitigation and workarounds

The issue has been resolved by updating all code to consistently use the control interpretation of platform_max. Additionally, comments have been added to the soc_mixer_control struct to prevent future patches from switching between the two approaches. The fix ensures that platform_max is consistently treated as a control value throughout the codebase (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74730CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 22, 2026
CVE-2026-74733HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesAug 22, 2026
CVE-2026-74726HIGH7.3
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesAug 22, 2026
CVE-2026-74732MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • kernel-selftests-internal
NoYesAug 22, 2026
CVE-2026-74728NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-modules-core
NoNoAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management