{"api_version":"1","generated_at":"2026-08-22T16:59:50+00:00","cve":"CVE-2025-38299","urls":{"html":"https://cve.report/CVE-2025-38299","api":"https://cve.report/api/cve/CVE-2025-38299.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-38299","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-38299"},"summary":{"title":"ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()\n\nETDM2_IN_BE and ETDM1_OUT_BE are defined as COMP_EMPTY(),\nin the case the codec dai_name will be null.\n\nAvoid a crash if the device tree is not assigning a codec\nto these links.\n\n[    1.179936] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[    1.181065] Mem abort info:\n[    1.181420]   ESR = 0x0000000096000004\n[    1.181892]   EC = 0x25: DABT (current EL), IL = 32 bits\n[    1.182576]   SET = 0, FnV = 0\n[    1.182964]   EA = 0, S1PTW = 0\n[    1.183367]   FSC = 0x04: level 0 translation fault\n[    1.183983] Data abort info:\n[    1.184406]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[    1.185097]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[    1.185766]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[    1.186439] [0000000000000000] user address but active_mm is swapper\n[    1.187239] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[    1.188029] Modules linked in:\n[    1.188420] CPU: 7 UID: 0 PID: 70 Comm: kworker/u32:1 Not tainted 6.14.0-rc4-next-20250226+ #85\n[    1.189515] Hardware name: Radxa NIO 12L (DT)\n[    1.190065] Workqueue: events_unbound deferred_probe_work_func\n[    1.190808] pstate: 40400009 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[    1.191683] pc : __pi_strcmp+0x24/0x140\n[    1.192170] lr : mt8195_mt6359_soc_card_probe+0x224/0x7b0\n[    1.192854] sp : ffff800083473970\n[    1.193271] x29: ffff800083473a10 x28: 0000000000001008 x27: 0000000000000002\n[    1.194168] x26: ffff800082408960 x25: ffff800082417db0 x24: ffff800082417d88\n[    1.195065] x23: 000000000000001e x22: ffff800082dbf480 x21: ffff800082dc07b8\n[    1.195961] x20: 0000000000000000 x19: 0000000000000013 x18: 00000000ffffffff\n[    1.196858] x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000006\n[    1.197755] x14: ffff800082407af0 x13: 6e6f69737265766e x12: 692d6b636f6c6374\n[    1.198651] x11: 0000000000000002 x10: ffff80008240b920 x9 : 0000000000000018\n[    1.199547] x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000\n[    1.200443] x5 : 0000000000000000 x4 : 8080808080000000 x3 : 303933383978616d\n[    1.201339] x2 : 0000000000000000 x1 : ffff80008240b920 x0 : 0000000000000000\n[    1.202236] Call trace:\n[    1.202545]  __pi_strcmp+0x24/0x140 (P)\n[    1.203029]  mtk_soundcard_common_probe+0x3bc/0x5b8\n[    1.203644]  platform_probe+0x70/0xe8\n[    1.204106]  really_probe+0xc8/0x3a0\n[    1.204556]  __driver_probe_device+0x84/0x160\n[    1.205104]  driver_probe_device+0x44/0x130\n[    1.205630]  __device_attach_driver+0xc4/0x170\n[    1.206189]  bus_for_each_drv+0x8c/0xf8\n[    1.206672]  __device_attach+0xa8/0x1c8\n[    1.207155]  device_initial_probe+0x1c/0x30\n[    1.207681]  bus_probe_device+0xb0/0xc0\n[    1.208165]  deferred_probe_work_func+0xa4/0x100\n[    1.208747]  process_one_work+0x158/0x3e0\n[    1.209254]  worker_thread+0x2c4/0x3e8\n[    1.209727]  kthread+0x134/0x1f0\n[    1.210136]  ret_from_fork+0x10/0x20\n[    1.210589] Code: 54000401 b50002c6 d503201f f86a6803 (f8408402)\n[    1.211355] ---[ end trace 0000000000000000 ]---","state":"PUBLISHED","assigner":"Linux","published_at":"2025-07-10 08:15:28","updated_at":"2026-08-03 10:16:26"},"problem_types":["CWE-476"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}}],"references":[{"url":"https://git.kernel.org/stable/c/45bd023c7a4ec12059912a631a74723746145e7e","name":"https://git.kernel.org/stable/c/45bd023c7a4ec12059912a631a74723746145e7e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7af317f7faaab09d5a78f24605057d11f5955115","name":"https://git.kernel.org/stable/c/7af317f7faaab09d5a78f24605057d11f5955115","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/87dbfe2b392df9621f6e522e5fa6fb8849ca92ab","name":"https://git.kernel.org/stable/c/87dbfe2b392df9621f6e522e5fa6fb8849ca92ab","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/183e7329d41d7a8e298f48b6b0eb81102a8654de","name":"https://git.kernel.org/stable/c/183e7329d41d7a8e298f48b6b0eb81102a8654de","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-38299","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-38299","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 81051a495a9a23c0339d2ae1aa6e4477ed7268c8 45bd023c7a4ec12059912a631a74723746145e7e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e70b8dd26711704b1ff1f1b4eb3d048ba69e29da 87dbfe2b392df9621f6e522e5fa6fb8849ca92ab git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e70b8dd26711704b1ff1f1b4eb3d048ba69e29da 183e7329d41d7a8e298f48b6b0eb81102a8654de git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e70b8dd26711704b1ff1f1b4eb3d048ba69e29da 7af317f7faaab09d5a78f24605057d11f5955115 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.34 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.15.3 6.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.16 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2025","cve_id":"38299","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["sound/soc/mediatek/mt8195/mt8195-mt6359.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"45bd023c7a4ec12059912a631a74723746145e7e","status":"affected","version":"81051a495a9a23c0339d2ae1aa6e4477ed7268c8","versionType":"git"},{"lessThan":"87dbfe2b392df9621f6e522e5fa6fb8849ca92ab","status":"affected","version":"e70b8dd26711704b1ff1f1b4eb3d048ba69e29da","versionType":"git"},{"lessThan":"183e7329d41d7a8e298f48b6b0eb81102a8654de","status":"affected","version":"e70b8dd26711704b1ff1f1b4eb3d048ba69e29da","versionType":"git"},{"lessThan":"7af317f7faaab09d5a78f24605057d11f5955115","status":"affected","version":"e70b8dd26711704b1ff1f1b4eb3d048ba69e29da","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["sound/soc/mediatek/mt8195/mt8195-mt6359.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.8"},{"lessThan":"6.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.34","versionType":"semver"},{"lessThanOrEqual":"6.15.*","status":"unaffected","version":"6.15.3","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"6.16","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.34","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.15.3","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.16","versionStartIncluding":"6.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()\n\nETDM2_IN_BE and ETDM1_OUT_BE are defined as COMP_EMPTY(),\nin the case the codec dai_name will be null.\n\nAvoid a crash if the device tree is not assigning a codec\nto these links.\n\n[    1.179936] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[    1.181065] Mem abort info:\n[    1.181420]   ESR = 0x0000000096000004\n[    1.181892]   EC = 0x25: DABT (current EL), IL = 32 bits\n[    1.182576]   SET = 0, FnV = 0\n[    1.182964]   EA = 0, S1PTW = 0\n[    1.183367]   FSC = 0x04: level 0 translation fault\n[    1.183983] Data abort info:\n[    1.184406]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[    1.185097]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[    1.185766]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[    1.186439] [0000000000000000] user address but active_mm is swapper\n[    1.187239] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[    1.188029] Modules linked in:\n[    1.188420] CPU: 7 UID: 0 PID: 70 Comm: kworker/u32:1 Not tainted 6.14.0-rc4-next-20250226+ #85\n[    1.189515] Hardware name: Radxa NIO 12L (DT)\n[    1.190065] Workqueue: events_unbound deferred_probe_work_func\n[    1.190808] pstate: 40400009 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[    1.191683] pc : __pi_strcmp+0x24/0x140\n[    1.192170] lr : mt8195_mt6359_soc_card_probe+0x224/0x7b0\n[    1.192854] sp : ffff800083473970\n[    1.193271] x29: ffff800083473a10 x28: 0000000000001008 x27: 0000000000000002\n[    1.194168] x26: ffff800082408960 x25: ffff800082417db0 x24: ffff800082417d88\n[    1.195065] x23: 000000000000001e x22: ffff800082dbf480 x21: ffff800082dc07b8\n[    1.195961] x20: 0000000000000000 x19: 0000000000000013 x18: 00000000ffffffff\n[    1.196858] x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000006\n[    1.197755] x14: ffff800082407af0 x13: 6e6f69737265766e x12: 692d6b636f6c6374\n[    1.198651] x11: 0000000000000002 x10: ffff80008240b920 x9 : 0000000000000018\n[    1.199547] x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000\n[    1.200443] x5 : 0000000000000000 x4 : 8080808080000000 x3 : 303933383978616d\n[    1.201339] x2 : 0000000000000000 x1 : ffff80008240b920 x0 : 0000000000000000\n[    1.202236] Call trace:\n[    1.202545]  __pi_strcmp+0x24/0x140 (P)\n[    1.203029]  mtk_soundcard_common_probe+0x3bc/0x5b8\n[    1.203644]  platform_probe+0x70/0xe8\n[    1.204106]  really_probe+0xc8/0x3a0\n[    1.204556]  __driver_probe_device+0x84/0x160\n[    1.205104]  driver_probe_device+0x44/0x130\n[    1.205630]  __device_attach_driver+0xc4/0x170\n[    1.206189]  bus_for_each_drv+0x8c/0xf8\n[    1.206672]  __device_attach+0xa8/0x1c8\n[    1.207155]  device_initial_probe+0x1c/0x30\n[    1.207681]  bus_probe_device+0xb0/0xc0\n[    1.208165]  deferred_probe_work_func+0xa4/0x100\n[    1.208747]  process_one_work+0x158/0x3e0\n[    1.209254]  worker_thread+0x2c4/0x3e8\n[    1.209727]  kthread+0x134/0x1f0\n[    1.210136]  ret_from_fork+0x10/0x20\n[    1.210589] Code: 54000401 b50002c6 d503201f f86a6803 (f8408402)\n[    1.211355] ---[ end trace 0000000000000000 ]---"}],"providerMetadata":{"dateUpdated":"2026-08-03T09:32:22.901Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/45bd023c7a4ec12059912a631a74723746145e7e"},{"url":"https://git.kernel.org/stable/c/87dbfe2b392df9621f6e522e5fa6fb8849ca92ab"},{"url":"https://git.kernel.org/stable/c/183e7329d41d7a8e298f48b6b0eb81102a8654de"},{"url":"https://git.kernel.org/stable/c/7af317f7faaab09d5a78f24605057d11f5955115"}],"title":"ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2025-38299","datePublished":"2025-07-10T07:42:12.216Z","dateReserved":"2025-04-16T04:51:24.002Z","dateUpdated":"2026-08-03T09:32:22.901Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-07-10 08:15:28","lastModifiedDate":"2026-08-03 10:16:26","problem_types":["CWE-476"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.12.34","matchCriteriaId":"15BC1D57-68F1-439E-BE58-136CEB32896A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.15.3","matchCriteriaId":"0541C761-BD5E-4C1A-8432-83B375D7EB92"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"38299","Ordinal":"1","Title":"ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()","CVE":"CVE-2025-38299","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"38299","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()\n\nETDM2_IN_BE and ETDM1_OUT_BE are defined as COMP_EMPTY(),\nin the case the codec dai_name will be null.\n\nAvoid a crash if the device tree is not assigning a codec\nto these links.\n\n[    1.179936] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[    1.181065] Mem abort info:\n[    1.181420]   ESR = 0x0000000096000004\n[    1.181892]   EC = 0x25: DABT (current EL), IL = 32 bits\n[    1.182576]   SET = 0, FnV = 0\n[    1.182964]   EA = 0, S1PTW = 0\n[    1.183367]   FSC = 0x04: level 0 translation fault\n[    1.183983] Data abort info:\n[    1.184406]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[    1.185097]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[    1.185766]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[    1.186439] [0000000000000000] user address but active_mm is swapper\n[    1.187239] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[    1.188029] Modules linked in:\n[    1.188420] CPU: 7 UID: 0 PID: 70 Comm: kworker/u32:1 Not tainted 6.14.0-rc4-next-20250226+ #85\n[    1.189515] Hardware name: Radxa NIO 12L (DT)\n[    1.190065] Workqueue: events_unbound deferred_probe_work_func\n[    1.190808] pstate: 40400009 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[    1.191683] pc : __pi_strcmp+0x24/0x140\n[    1.192170] lr : mt8195_mt6359_soc_card_probe+0x224/0x7b0\n[    1.192854] sp : ffff800083473970\n[    1.193271] x29: ffff800083473a10 x28: 0000000000001008 x27: 0000000000000002\n[    1.194168] x26: ffff800082408960 x25: ffff800082417db0 x24: ffff800082417d88\n[    1.195065] x23: 000000000000001e x22: ffff800082dbf480 x21: ffff800082dc07b8\n[    1.195961] x20: 0000000000000000 x19: 0000000000000013 x18: 00000000ffffffff\n[    1.196858] x17: 000000040044ffff x16: 005000f2b5503510 x15: 0000000000000006\n[    1.197755] x14: ffff800082407af0 x13: 6e6f69737265766e x12: 692d6b636f6c6374\n[    1.198651] x11: 0000000000000002 x10: ffff80008240b920 x9 : 0000000000000018\n[    1.199547] x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000\n[    1.200443] x5 : 0000000000000000 x4 : 8080808080000000 x3 : 303933383978616d\n[    1.201339] x2 : 0000000000000000 x1 : ffff80008240b920 x0 : 0000000000000000\n[    1.202236] Call trace:\n[    1.202545]  __pi_strcmp+0x24/0x140 (P)\n[    1.203029]  mtk_soundcard_common_probe+0x3bc/0x5b8\n[    1.203644]  platform_probe+0x70/0xe8\n[    1.204106]  really_probe+0xc8/0x3a0\n[    1.204556]  __driver_probe_device+0x84/0x160\n[    1.205104]  driver_probe_device+0x44/0x130\n[    1.205630]  __device_attach_driver+0xc4/0x170\n[    1.206189]  bus_for_each_drv+0x8c/0xf8\n[    1.206672]  __device_attach+0xa8/0x1c8\n[    1.207155]  device_initial_probe+0x1c/0x30\n[    1.207681]  bus_probe_device+0xb0/0xc0\n[    1.208165]  deferred_probe_work_func+0xa4/0x100\n[    1.208747]  process_one_work+0x158/0x3e0\n[    1.209254]  worker_thread+0x2c4/0x3e8\n[    1.209727]  kthread+0x134/0x1f0\n[    1.210136]  ret_from_fork+0x10/0x20\n[    1.210589] Code: 54000401 b50002c6 d503201f f86a6803 (f8408402)\n[    1.211355] ---[ end trace 0000000000000000 ]---","Type":"Description","Title":"ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()"}]}}}