CVE-2025-37811
In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: ci_hdrc_imx: fix usbmisc handling usbmisc is an optional device property so it is totally valid for the corresponding data->usbmisc_data to have a NULL value.
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: ci_hdrc_imx: fix usbmisc handling usbmisc is an optional device property so it is totally valid for the corresponding data->usbmisc_data to have a NULL value. Check that before dereferencing the pointer. Found by Linux Verification Center (linuxtesting.org) with Svace static analysis tool.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0ee460498ced49196149197c9f6d29a10e5e0798Patch
- https://git.kernel.org/stable/c/121e9f80ea5478bca3a8f3f26593fd66f87da649Patch
- https://git.kernel.org/stable/c/2aa87bd825377f5073b76701780a902cd0fc725aPatch
- https://git.kernel.org/stable/c/4e28f79e3dffa52d327b46d1a78dac16efb5810bPatch
- https://git.kernel.org/stable/c/8060b719676e8c0e5a2222c2977ba0458d9d9535Patch
- https://git.kernel.org/stable/c/887902ca73490f38c69fd6149ef361a041cf912fPatch
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.htmlMailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.