CVE-2025-68281 addresses a bug in the Linux kernel's ASoC SDCA component, specifically within the mipi-sdca-control-cn-list parsing. The vulnerability arises from a memory allocation mismatch where the "values" field of "struct sdca_control" is declared as an integer array but allocated as a character array, leading to crashes in the sdca_parse_function API. While no CVSS score is provided, its FAUCET Risk Score is 7/100, suggesting a low severity with potential for system instability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.17CNA affecteddefault affected | |
| Linux | Linux | >= 50a479527ef01f9b36dde1803a7e81741a222509, < eb2d6774cc0d9d6ab8f924825695a85c14b2e0c2, >= 50a479527ef01f9b36dde1803a7e81741a222509, < fcd5786b506c51cbabc2560c68e040d8dba22a0dCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (OEM) vulnerabilities
Apr 6, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Real-time) vulnerabilities
Mar 23, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: ASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list
Dec 16, 2025ASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list
Dec 9, 2025