CVE-2025-21847: ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data()
Published Mar 12, 2025
·Updated
ASoC: SOF: stream-ipc: Check for cstream nullity in sofipcmsgdata()
Affected Software
13 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.82.1-1
Microsoft azl3 kernel 6.6.78.1-3
Linux Linux kernel>=6.3<6.6.80
Linux Linux kernel>=6.7<6.12.17
Linux Linux kernel>=6.13<6.13.5
Linux Linux kernel=6.14-rc1
Linux Linux kernel=6.14-rc2
Linux Linux kernel=6.14-rc3
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
Event History
Mar 12, 2025
CVE Published
via MITRE·09:42 AM
Data Sourced
via MITRE·09:42 AM
Description
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·12:23 PM
DescriptionSeverityAffected Software
Apr 9, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21847?
CVE-2025-21847 has been classified with a high severity rating due to its potential impact on system stability and functionality.
2
How do I fix CVE-2025-21847?
To resolve CVE-2025-21847, update your Linux kernel to the latest version that includes the fix for the vulnerability.
3
What systems are affected by CVE-2025-21847?
CVE-2025-21847 affects the Linux kernel; ensure your system is running an up-to-date version to mitigate risks.
4
What exploitation methods are associated with CVE-2025-21847?
The exploitation of CVE-2025-21847 could lead to potential denial of service or system crashes due to improper handling of IPC messages.
5
Is there a workaround for CVE-2025-21847?
Currently, there is no documented workaround for CVE-2025-21847; the recommended action is to apply security updates.