CVE-2025-38486
Linux Ubuntu vulnerability analysis and mitigation

Overview

A vulnerability was discovered in the Linux kernel's soundwire subsystem, identified as CVE-2025-38486. The issue was found in the implementation of the set_channel_map API support for Qualcomm's soundwire driver, which caused system crashes on Dragonboard 845c (sdm845) hardware. The vulnerability was disclosed on July 28, 2025 (NVD).

Technical details

The vulnerability stems from multiple implementation flaws in the soundwire Qualcomm driver. The issues include incorrect array indexing where the zeroth element of ctrl->pconfig[] is incorrectly used, array bounds violation in tx_ch[] array handling, and improper handling of tx information. These issues result in a kernel BRK exception at EL1 with an internal error in the BRK handler, leading to a kernel panic (NVD).

Impact

When triggered, the vulnerability causes a kernel panic with the message 'BRK handler: Fatal exception', making the system unstable and potentially unusable. This particularly affects systems using the Dragonboard 845c (sdm845) hardware (NVD).

Mitigation and workarounds

The issue has been resolved by reverting the commit 7796c97df6b1b2206681a07f3c80f6023a6593d5 which introduced the problematic set_channel_map API support. This reversion addresses all three identified bugs in the original implementation (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21441HIGH8.9
  • PythonPython
  • fence-agents-ibm-powervs
NoYesJan 07, 2026
CVE-2025-13151HIGH7.5
  • Linux DebianLinux Debian
  • libtasn1-6
NoYesJan 07, 2026
CVE-2025-68766HIGH7.1
  • Linux DebianLinux Debian
  • linux
NoYesJan 05, 2026
CVE-2025-68765MEDIUM5.5
  • Linux DebianLinux Debian
  • linux-azure-fde
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-core
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management