CVE Database
/

CVE-2025-40085

Back to search

CVE-2025-40085

Published: Oct 29, 2025

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card In try_to_register_card(), the return value of usb_ifnum_to_if() is passed directly to usb_interface_claimed() without a NULL check, which will lead to a NULL pointer dereference when creating an invalid USB audio device. Fix this by adding a check to ensure the interface pointer is valid before passing it to usb_interface_claimed().

VendorProductVersions

Linux

Linux

affected
28787ff9fbeaf57684eb64cc33e2ec8ceedf21b5 - < 736159f7b296d7a95f7208eb4799639b1f8b16a0
affected
39efc9c8a973ddff5918191525d1679d0fb368ea - < 8d19a7ab28c7b9c207db5c5282afa8cc8595bcdb
affected
39efc9c8a973ddff5918191525d1679d0fb368ea - < 576312eb436326b44b7010f4d9ae2b698df075ea
affected
39efc9c8a973ddff5918191525d1679d0fb368ea - < bba7208765d26e5e36b87f21dacc2780b064f41f
affected
39efc9c8a973ddff5918191525d1679d0fb368ea - < 8503ac1a62075a085402e42a386b5c627c821a51

+6 more versions

Linux

Linux

affected
6.1
unaffected
0 - < 6.1
unaffected
5.15.196 - <= 5.15.*
unaffected
6.1.158 - <= 6.1.*
unaffected
6.6.114 - <= 6.6.*

+3 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now