In the Linux kernel, the following vulnerability has been resolved: ASoC: tlv320adcx140: fix null pointer The "snd_soc_component" in "adcx140_priv" was only used once but never set. It was only used for reaching "dev" which is already present in "adcx140_priv".
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026012536-CVE-2026-23006-241b@gregkh/T