SB2025042299 - NULL pointer dereference in Linux kernel net usb driver
Published: April 22, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-22050)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the drivers/net/usb/usbnet.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0c30988588b28393e3e8873d5654f910e86391ba
- https://git.kernel.org/stable/c/0f10f83acfd619e13c64d6705908dfd792f19544
- https://git.kernel.org/stable/c/51de3600093429e3b712e5f091d767babc5dd6df
- https://git.kernel.org/stable/c/95789c2f94fd29dce8759f9766baa333f749287c
- https://git.kernel.org/stable/c/acacd48a37b52fc95f621765762c04152b58d642
- https://git.kernel.org/stable/c/d689645cd1594ea1d13cb0c404f8ad1011353e0e
- https://git.kernel.org/stable/c/fd9ee3f0d6a53844f65efde581c91bbb0ff749ac
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.2