CVE-2025-40085
Published Oct 29, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card In try_to_register_card(), the return value of usb_ifnum_to_if() is passed directly to usb_interface_claimed() without a NULL check, which will lead to a NULL pointer dereference when creating an invalid USB audio device. Fix this by adding a check to ensure the interface pointer is valid before passing it to usb_interface_claimed().
Is your site exposed to CVE-2025-40085?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/28412b489b088fb88dff488305fd4e56bd47f6e4
https://git.kernel.org/stable/c/576312eb436326b44b7010f4d9ae2b698df075ea
https://git.kernel.org/stable/c/736159f7b296d7a95f7208eb4799639b1f8b16a0
https://git.kernel.org/stable/c/8503ac1a62075a085402e42a386b5c627c821a51
https://git.kernel.org/stable/c/8d19a7ab28c7b9c207db5c5282afa8cc8595bcdb
https://git.kernel.org/stable/c/bba7208765d26e5e36b87f21dacc2780b064f41f
Frequently Asked Questions
What is CVE-2025-40085? +
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card
In try_to_register_card(), the return value of usb_ifnum_to_if() is
passed directly to usb_interface_claimed() without a NULL check, which
will lead to a NULL pointer dereference when creating an invalid
USB audio device. Fix this by adding a check to ensure the interface
pointer is valid before passing it to usb_interface_claimed().
How do I check if I'm vulnerable to CVE-2025-40085? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.