Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: tas2781: Fix wrong reference of tasdevice_priv During the conversion to unify the calibration data management, the reference to tasdevice_priv was wrongly set to h->hda_priv instead of h->priv. This resulted in memory corruption and crashes eventually. Unfortunately it's a void pointer, hence the compiler couldn't know that it's wrong.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.16, < 6.16.4 |
References
- https://git.kernel.org/stable/c/2812815aa79637d39d4398ecd7e58f65d1c79231Patch
- https://git.kernel.org/stable/c/3f4422e7c9436abf81a00270be7e4d6d3760ec0ePatch
FAQ
What is CVE-2025-39696?
CVE-2025-39696 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: tas2781: Fix wrong reference of tasdevice_priv During the conversion to unify the calibration data management, the refe...
How severe is CVE-2025-39696?
CVE-2025-39696 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-39696?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.