CVE-2025-68345: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi() The acpi_get_first_physical_node() function can return NULL, in which case the get_device() function also returns NULL, but this value is then dereferenced without checking,so add a check to prevent a crash. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Affected products
- Linux Linux: from 5.17, before 6.1.160 (fixed in 6.1.160); from 6.2, before 6.6.120 (fixed in 6.6.120); from 6.7, before 6.12.64 (fixed in 6.12.64); from 6.13, before 6.17.13 (fixed in 6.17.13); from 6.18, before 6.18.2 (fixed in 6.18.2)
Published 2025-12-24. Last modified 2026-06-17.