CVE-2025-40085
Last modified
CVE-2025-40085 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card In try_to_register_card(), the return value of usb_ifnum_to_if() is passed directly to usb_interface_claimed() without a NULL check, which will lead to a NULL pointer dereference when creating an invalid USB audio device. Fix this by adding a check to ensure the interface pointer is valid before passing it to usb_interface_claimed().. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card In try_to_register_card(), the return value of usb_ifnum_to_if() is passed directly to usb_interface_claimed() without a NULL check, which will lead to a NULL pointer dereference when creating an invalid USB audio device. Fix this by adding a check to ensure the interface pointer is valid before passing it to usb_interface_claimed().
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 28787ff9fbeaf57684eb64cc33e2ec8ceedf21b5, < 736159f7b296d7a95f7208eb4799639b1f8b16a0; >= 39efc9c8a973ddff5918191525d1679d0fb368ea, < 8d19a7ab28c7b9c207db5c5282afa8cc8595bcdb; >= 39efc9c8a973ddff5918191525d1679d0fb368ea, < 576312eb436326b44b7010f4d9ae2b698df075ea; >= 39efc9c8a973ddff5918191525d1679d0fb368ea, < bba7208765d26e5e36b87f21dacc2780b064f41f; >= 39efc9c8a973ddff5918191525d1679d0fb368ea, < 8503ac1a62075a085402e42a386b5c627c821a51; >= 39efc9c8a973ddff5918191525d1679d0fb368ea, < 28412b489b088fb88dff488305fd4e56bd47f6e4; 9d4f4dc3cd38e412c29a7626489fe48b79ebbf6c; 52076a41c128146c9df4a157e972cb17019313b1; >= 5.15.75, < 5.15.196; >= 5.19.17, < 5.20; >= 6.0.3, < 6.1 |
| Linux | Linux | 6.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40085?
How severe is CVE-2025-40085?
How do I fix CVE-2025-40085?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4008The Meteobridge web interface let meteobridge administrator …8.8
- CVE-2025-40080In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40081In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40082In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-40083In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40084In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-40086In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40087In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2025-40088In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-40089In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4009The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Swi…9.3
- CVE-2025-40090In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2025-40085?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
