{"id":"DEBIAN-CVE-2025-39765","details":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: timer: fix ida_free call while not allocated  In the snd_utimer_create() function, if the kasprintf() function return NULL, snd_utimer_put_id() will be called, finally use ida_free() to free the unallocated id 0.  the syzkaller reported the following information:   ------------[ cut here ]------------   ida_free called for id=0 which is not allocated.   WARNING: CPU: 1 PID: 1286 at lib/idr.c:592 ida_free+0x1fd/0x2f0 lib/idr.c:592   Modules linked in:   CPU: 1 UID: 0 PID: 1286 Comm: syz-executor164 Not tainted 6.15.8 #3 PREEMPT(lazy)   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-4.fc42 04/01/2014   RIP: 0010:ida_free+0x1fd/0x2f0 lib/idr.c:592   Code: f8 fc 41 83 fc 3e 76 69 e8 70 b2 f8 (...)   RSP: 0018:ffffc900007f79c8 EFLAGS: 00010282   RAX: 0000000000000000 RBX: 1ffff920000fef3b RCX: ffffffff872176a5   RDX: ffff88800369d200 RSI: 0000000000000000 RDI: ffff88800369d200   RBP: 0000000000000000 R08: ffffffff87ba60a5 R09: 0000000000000000   R10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000000   R13: 0000000000000002 R14: 0000000000000000 R15: 0000000000000000   FS:  00007f6f1abc1740(0000) GS:ffff8880d76a0000(0000) knlGS:0000000000000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   CR2: 00007f6f1ad7a784 CR3: 000000007a6e2000 CR4: 00000000000006f0   Call Trace:    \u003cTASK\u003e    snd_utimer_put_id sound/core/timer.c:2043 [inline] [snd_timer]    snd_utimer_create+0x59b/0x6a0 sound/core/timer.c:2184 [snd_timer]    snd_utimer_ioctl_create sound/core/timer.c:2202 [inline] [snd_timer]    __snd_timer_user_ioctl.isra.0+0x724/0x1340 sound/core/timer.c:2287 [snd_timer]    snd_timer_user_ioctl+0x75/0xc0 sound/core/timer.c:2298 [snd_timer]    vfs_ioctl fs/ioctl.c:51 [inline]    __do_sys_ioctl fs/ioctl.c:907 [inline]    __se_sys_ioctl fs/ioctl.c:893 [inline]    __x64_sys_ioctl+0x198/0x200 fs/ioctl.c:893    do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]    do_syscall_64+0x7b/0x160 arch/x86/entry/syscall_64.c:94    entry_SYSCALL_64_after_hwframe+0x76/0x7e   [...]  The utimer-\u003eid should be set properly before the kasprintf() function, ensures the snd_utimer_put_id() function will free the allocated id.","modified":"2026-08-27T23:05:31.652788950Z","published":"2025-09-11T17:15:40.807Z","upstream":["CVE-2025-39765"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-39765"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.48-1"}]}],"versions":["6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-39765.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.16.5-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.3-1","6.16.3-1~bpo13+1","6.16~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-39765.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}