5.5

CVE-2025-71081

ASoC: stm32: sai: fix OF node leak on probe

In the Linux kernel, the following vulnerability has been resolved:

ASoC: stm32: sai: fix OF node leak on probe

The reference taken to the sync provider OF node when probing the
platform device is currently only dropped if the set_sync() callback
fails during DAI probe.

Make sure to drop the reference on platform probe failures (e.g. probe
deferral) and on driver unbind.

This also avoids a potential use-after-free in case the DAI is ever
reprobed without first rebinding the platform driver.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.15.1 < 5.15.198
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.160
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.120
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.64
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.4
Linux ≫ Linux Kernel Version 4.15 Update -
Linux ≫ Linux Kernel Version 6.19 Update rc1
Linux ≫ Linux Kernel Version 6.19 Update rc2
Linux ≫ Linux Kernel Version 6.19 Update rc3
Linux ≫ Linux Kernel Version 6.19 Update rc4
Linux ≫ Linux Kernel Version 6.19 Update rc5
Linux ≫ Linux Kernel Version 6.19 Update rc6
Linux ≫ Linux Kernel Version 6.19 Update rc7
Linux ≫ Linux Kernel Version 6.19 Update rc8
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.018
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://git.kernel.org/stable/c/acda653169e180b1d860dbb6bc5aceb105858394
Patch
https://git.kernel.org/stable/c/4054a3597d047f3fe87864ef87f399b5d523e6c0
Patch
https://git.kernel.org/stable/c/bae74771fc5d3b2a9cf6f5aa64596083d032c4a3
Patch
https://git.kernel.org/stable/c/3752afcc6d80d5525e236e329895ba2cb93bcb26
Patch
https://git.kernel.org/stable/c/23261f0de09427367e99f39f588e31e2856a690e
Patch
https://git.kernel.org/stable/c/7daa50a2157e41c964b745ab1dc378b5b3b626d1
Patch