CVE-2025-23146

MEDIUM EPSS 6.6%
Published May 1, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 1, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: mfd: ene-kb3930: Fix a potential NULL pointer dereference The off_gpios could be NULL. Add missing check in the kb3930_probe(). This is similar to the issue fixed in commit b1ba8bcb2d1f ("backlight: hx8357: Fix potential NULL pointer dereference"). This was detected by our static analysis tool.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
6.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 8

VendorProductVersionRange
linuxlinux_kernel*≥5.10  –  <5.10.237
linuxlinux_kernel*≥5.11  –  <5.15.181
linuxlinux_kernel*≥5.16  –  <6.1.135
linuxlinux_kernel*≥6.2  –  <6.6.88
linuxlinux_kernel*≥6.7  –  <6.12.24
linuxlinux_kernel*≥6.13  –  <6.13.12
linuxlinux_kernel*≥6.14  –  <6.14.3
debiandebian_linux11.0any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/2edb5b29b197d90b4d08cd45e911c0bcf24cb895
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4cdf1d2a816a93fa02f7b6b5492dc7f55af2a199
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6dc88993ee3fa8365ff6a5d6514702f70ba6863a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/76d0f4199bc5b51acb7b96c6663a8953543733ad
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7b47df6498f223c8956bfe0d994a0e42a520dfcd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/90ee23c2514a22a9c2bb39a540cbe1c9acb27d0b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b1758417310d2cc77e52cd15103497e52e2614f6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ea07760676bba49319d553af80c239da053b5fb1
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
    Mailing List
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
    Mailing List

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/2edb5b29b197d90b4d08cd45e911c0bcf24cb895
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4cdf1d2a816a93fa02f7b6b5492dc7f55af2a199
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6dc88993ee3fa8365ff6a5d6514702f70ba6863a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/76d0f4199bc5b51acb7b96c6663a8953543733ad
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7b47df6498f223c8956bfe0d994a0e42a520dfcd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/90ee23c2514a22a9c2bb39a540cbe1c9acb27d0b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b1758417310d2cc77e52cd15103497e52e2614f6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ea07760676bba49319d553af80c239da053b5fb1
    Patch