CVE-2025-21918

MEDIUM EPSS 7.4%
Published Apr 1, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Apr 1, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Fix NULL pointer access Resources should be released only after all threads that utilize them have been destroyed. This commit ensures that resources are not released prematurely by waiting for the associated workqueue to complete before deallocating them.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
7.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥5.16  –  <6.1.133
linuxlinux_kernel*≥6.2  –  <6.6.83
linuxlinux_kernel*≥6.7  –  <6.12.19
linuxlinux_kernel*≥6.13  –  <6.13.7
linuxlinux_kernel6.14any
linuxlinux_kernel6.14any
linuxlinux_kernel6.14any
linuxlinux_kernel6.14any
linuxlinux_kernel6.14any

References 6

  • git.kernel.org https://git.kernel.org/stable/c/079a3e52f3e751bb8f5937195bdf25c5d14fdff0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/46fba7be161bb89068958138ea64ec33c0b446d4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/592a0327d026a122e97e8e8bb7c60cbbe7697344
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7a735a8a46f6ebf898bbefd96659ca5da798bce0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b13abcb7ddd8d38de769486db5bd917537b32ab1
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/079a3e52f3e751bb8f5937195bdf25c5d14fdff0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/46fba7be161bb89068958138ea64ec33c0b446d4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/592a0327d026a122e97e8e8bb7c60cbbe7697344
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7a735a8a46f6ebf898bbefd96659ca5da798bce0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b13abcb7ddd8d38de769486db5bd917537b32ab1
    Patch