
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2025-40162) was discovered in the Linux kernel's ASoC AMD SoundWire utilities component. The issue was disclosed on November 12, 2025, affecting the Linux kernel's audio subsystem. The vulnerability stems from a potential NULL pointer dereference in the debug message handling when devm_kasprintf() fails (NVD).
The vulnerability occurs in the AMD SoundWire utilities where devmkasprintf() may return NULL on memory allocation failure. The debug message attempts to print cpus->dainame before checking if the pointer is NULL, which could lead to a NULL pointer dereference. The fix involves moving the dev_dbg() call after the NULL check to prevent the potential dereference (Debian Tracker).
The vulnerability could potentially cause a system crash due to NULL pointer dereference in the Linux kernel's audio subsystem, specifically affecting the AMD SoundWire functionality (NVD).
The issue has been fixed in various Linux distributions including Debian Bookworm (6.1.158-1), Trixie (6.12.57-1), and Forky (6.17.8-1). Users are advised to update their systems to the patched versions (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."