---
id: CVE-2025-40097
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ALSA: hda: Fix missing pointer check in hda_component_manager_init function

  The __component_match_add function may assign the 'matchptr' pointer
  the value ERR_PTR(-ENO…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ALSA: hda: Fix missing pointer check in hda_component_manager_init function

  The __component_match_add function may assign the 'matchptr' pointer
  the value ERR_PTR(-ENO…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= ae7abe36e352eddf8e30d3b1ea3fb402514ba13b <
    b044aa6ae63391ba40c93ca5d476d276cb17db1b
  - >-
    Linux >= ae7abe36e352eddf8e30d3b1ea3fb402514ba13b <
    1c3f4b15eb1850558d7d4da74b98cffbb8121721
  - >-
    Linux >= ae7abe36e352eddf8e30d3b1ea3fb402514ba13b <
    218a8504e62fc2c8a1fd12523346b7a2b9bd2474
  - >-
    Linux >= ae7abe36e352eddf8e30d3b1ea3fb402514ba13b <
    47d1b9ca923b55c3f407788f1f15b04957e0e027
  - >-
    Linux >= ae7abe36e352eddf8e30d3b1ea3fb402514ba13b <
    1cf11d80db5df805b538c942269e05a65bcaf5bc
  - Linux 5.17
published: '2025-10-30'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:33.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40097'
references:
  - url: 'https://git.kernel.org/stable/c/1c3f4b15eb1850558d7d4da74b98cffbb8121721'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1cf11d80db5df805b538c942269e05a65bcaf5bc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/218a8504e62fc2c8a1fd12523346b7a2b9bd2474'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/47d1b9ca923b55c3f407788f1f15b04957e0e027'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b044aa6ae63391ba40c93ca5d476d276cb17db1b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00197
epssPercentile: 0.08493
ingestedAt: '2026-10-03T11:43:42.110Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ALSA: hda: Fix missing pointer check in hda_component_manager_init function

The __component_match_add function may assign the 'matchptr' pointer
the value ERR_PTR(-ENOMEM), which will subsequently be dereferenced.

The call stack leading to the error looks like this:

hda_component_manager_init
|-> component_match_add
    |-> component_match_add_release
        |-> __component_match_add ( ... ,**matchptr, ... )
            |-> *matchptr = ERR_PTR(-ENOMEM);       // assign
|-> component_master_add_with_match( ...  match)
    |-> component_match_realloc(match, match->num); // dereference

Add IS_ERR() check to prevent the crash.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
