---
id: CVE-2025-21870
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers

  Other, non DAI copier widgets could have the same  stream name (sname) as
  the ALH copier and in that …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers

  Other, non DAI copier widgets could have the same  stream name (sname) as
  the ALH copier and in that …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-476
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.0, < 6.12.17'
  - 'linux_kernel >= 6.13, < 6.13.5'
  - linux_kernel = 6.14
patched:
  - linux_kernel 6.13.5
published: '2025-03-27'
updated: '2026-07-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21870'
references:
  - url: 'https://git.kernel.org/stable/c/6fd60136d256b3b948333ebdb3835f41a95ab7ef'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/87c8768a96092ce75cd47fe076db5080db7ac515'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/93c6c2e5801aab09ef1ef99f248f3cd323c3f152'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00202
epssPercentile: 0.08866
ingestedAt: '2026-07-30T06:53:10.621Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers

Other, non DAI copier widgets could have the same  stream name (sname) as
the ALH copier and in that case the copier->data is NULL, no alh_data is
attached, which could lead to NULL pointer dereference.
We could check for this NULL pointer in sof_ipc4_prepare_copier_module()
and avoid the crash, but a similar loop in sof_ipc4_widget_setup_comp_dai()
will miscalculate the ALH device count, causing broken audio.

The correct fix is to harden the matching logic by making sure that the
1. widget is a DAI widget - so dai = w->private is valid
2. the dai (and thus the copier) is ALH copier

## Affected

- `linux_kernel >= 6.0, < 6.12.17`
- `linux_kernel >= 6.13, < 6.13.5`
- `linux_kernel = 6.14`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.13.5`
