CVE-2025-22054

MEDIUM EPSS 7.1%
Published Apr 16, 20251y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Apr 16, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: arcnet: Add NULL check in com20020pci_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, com20020pci_probe() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue and ensure no resources are left allocated.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
7.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥4.19.302  –  <4.20
linuxlinux_kernel*≥5.4.264  –  <5.4.292
linuxlinux_kernel*≥5.10.204  –  <5.10.236
linuxlinux_kernel*≥5.15.143  –  <5.15.180
linuxlinux_kernel*≥6.1.68  –  <6.1.134
linuxlinux_kernel*≥6.6.7  –  <6.6.87
linuxlinux_kernel*≥6.7  –  <6.12.23
linuxlinux_kernel*≥6.13  –  <6.13.11
linuxlinux_kernel*≥6.14  –  <6.14.2

References 11

  • git.kernel.org https://git.kernel.org/stable/c/661cf5d102949898c931e81fd4e1c773afcdeafa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/887226163504494ea7e58033a97c2d2ab12e05d4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/905a34dc1ad9a53a8aaaf8a759ea5dbaaa30418d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a654f31b33515d39bb56c75fd8b26bef025ced7e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/be8a0decd0b59a52a07276f9ef3b33ef820b2179
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ebebeb58d48e25525fa654f2c53a24713fe141c3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ececf8eff6c25acc239fa8f0fd837c76bc770547
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ef8b29398ea6061ac8257f3e45c9be45cc004ce2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fda8c491db2a90ff3e6fbbae58e495b4ddddeca3
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/661cf5d102949898c931e81fd4e1c773afcdeafa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/887226163504494ea7e58033a97c2d2ab12e05d4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/905a34dc1ad9a53a8aaaf8a759ea5dbaaa30418d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a654f31b33515d39bb56c75fd8b26bef025ced7e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/be8a0decd0b59a52a07276f9ef3b33ef820b2179
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ebebeb58d48e25525fa654f2c53a24713fe141c3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ececf8eff6c25acc239fa8f0fd837c76bc770547
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ef8b29398ea6061ac8257f3e45c9be45cc004ce2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fda8c491db2a90ff3e6fbbae58e495b4ddddeca3
    Patch