In the Linux kernel, the following vulnerability has been resolved:
usb: chipidea: ci_hdrc_imx: fix usbmisc handling
usbmisc is an optional device property so it is totally valid for the
corresponding data->usbmisc_data to have a NULL value.
Check that before dereferencing the pointer.
Found by Linux Verification Center (linuxtesting.org) with Svace static
analysis tool.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
12 Nov 2025, 21:40
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-476 | |
| First Time |
Debian debian Linux
Linux Debian Linux linux Kernel |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CPE | cpe:2.3:o:linux:linux_kernel:6.13:-:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.13:rc7:*:*:*:*:*:* |
|
| References | () https://git.kernel.org/stable/c/0ee460498ced49196149197c9f6d29a10e5e0798 - Patch | |
| References | () https://git.kernel.org/stable/c/121e9f80ea5478bca3a8f3f26593fd66f87da649 - Patch | |
| References | () https://git.kernel.org/stable/c/2aa87bd825377f5073b76701780a902cd0fc725a - Patch | |
| References | () https://git.kernel.org/stable/c/4e28f79e3dffa52d327b46d1a78dac16efb5810b - Patch | |
| References | () https://git.kernel.org/stable/c/8060b719676e8c0e5a2222c2977ba0458d9d9535 - Patch | |
| References | () https://git.kernel.org/stable/c/887902ca73490f38c69fd6149ef361a041cf912f - Patch | |
| References | () https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html - Mailing List, Third Party Advisory |
03 Nov 2025, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 May 2025, 14:39
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
08 May 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-08 07:15
Updated : 2025-11-12 21:40
NVD link : CVE-2025-37811
Mitre link : CVE-2025-37811
CVE.ORG link : CVE-2025-37811
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
CWE-476
NULL Pointer Dereference
