CVE-2025-38143
In the Linux kernel, the following vulnerability has been resolved: backlight: pm8941: Add NULL check in wled_configure() devm_kasprintf() returns NULL when memory allocation fails.
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: backlight: pm8941: Add NULL check in wled_configure() devm_kasprintf() returns NULL when memory allocation fails. Currently, wled_configure() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.18% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1be2000b703b02e149f8f2061054489f6c18c972Patch
- https://git.kernel.org/stable/c/21528806560510458378ea52c37e35b0773afaeaPatch
- https://git.kernel.org/stable/c/4a715be3fe80b68fa55cb3569af3d294be101626Patch
- https://git.kernel.org/stable/c/6a56446595730a5e3f06a30902e23cb037d28146Patch
- https://git.kernel.org/stable/c/9d06ac32c202142da40904180f2669ed4f5073acPatch
- https://git.kernel.org/stable/c/e12d3e1624a02706cdd3628bbf5668827214fa33Patch
- https://git.kernel.org/stable/c/fde314445332015273c8f51d2659885c606fe135Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.