CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-37941: ASoC: codecs: wcd937x: fix a potential memory leak in wcd937x_soc_codec_probe()

Description

In the Linux kernel, the following vulnerability has been resolved:

ASoC: codecs: wcd937x: fix a potential memory leak in wcd937x_soc_codec_probe()

When snd_soc_dapm_new_controls() or snd_soc_dapm_add_routes() fails,
wcd937x_soc_codec_probe() returns without releasing 'wcd937x->clsh_info',
which is allocated by wcd_clsh_ctrl_alloc. Add wcd_clsh_ctrl_free()
to prevent potential memory leak.

Classification

CVE ID: CVE-2025-37941

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 4.6% (scored less or equal to compared to others)

EPSS Date: 2025-06-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-37941
https://git.kernel.org/stable/c/acadb2e2b3c5b9977a843a3a94fece9bdcf6aea1
https://git.kernel.org/stable/c/b573e04116fd33b9143fa276bbab2f0afad0a1ae
https://git.kernel.org/stable/c/aafb5325aca3e806b3ea3707402189263473d257
https://git.kernel.org/stable/c/3e330acf4efd63876d673c046cd073a1d4ed57a8

Timeline