Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Verify content returned by parse_int_array() The first element of the returned array stores its length. If it is 0, any manipulation beyond the element at index 0 ends with null-ptr-deref.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.2, < 6.6.94 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/18ff538aac63de1866e5a49d57e22788b5c21d12Patch
- https://git.kernel.org/stable/c/2916794ffbce604cc2cda105f6b8a4a7c748dd7fPatch
- https://git.kernel.org/stable/c/93e246b6769bdacb09cfff4ea0f00fe5ab4f0d7aPatch
- https://git.kernel.org/stable/c/cc03c899e6d9812b25c3754c9a95c3830c4aec26Patch
FAQ
What is CVE-2025-38307?
CVE-2025-38307 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Verify content returned by parse_int_array() The first element of the returned array stores its length. If it is...
How severe is CVE-2025-38307?
CVE-2025-38307 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-38307?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.