CVE-2025-38160
In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() devm_kasprintf() returns NULL when memory allocation fails.
Does this matter?
Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() devm_kasprintf() returns NULL when memory allocation fails. Currently, raspberrypi_clk_register() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.16% probability · 5th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0a2712cd24ecfeb520af60f6f859b442c7ab01ffPatch
- https://git.kernel.org/stable/c/1b69a5299f28ce8e6afa37c3690dbc14c3a1f53fPatch
- https://git.kernel.org/stable/c/3c1adc2f8c732ea09e8c4bce5941fec019c6205dPatch
- https://git.kernel.org/stable/c/52562161df3567cdaedada46834a7a8d8c4ab737Patch
- https://git.kernel.org/stable/c/54ce9bcdaee59d4ef0703f390d55708557818f9ePatch
- https://git.kernel.org/stable/c/73c46d9a93d071ca69858dea3f569111b03e549ePatch
- https://git.kernel.org/stable/c/938f625bd3364cfdc93916739add3b637ff90368Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.