NULL pointer dereference in Linux kernel - CVE-2025-23147
Published: May 2, 2025 / Updated: May 10, 2025
Vulnerability identifier: #VU108298
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-23147
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the i3c_master_unregister_i3c_devs() function in drivers/i3c/master.c. A local user can perform a denial of service (DoS) attack.
How to mitigate CVE-2025-23147
Install update from vendor's website.
Sources
- https://git.kernel.org/stable/c/09359e7c8751961937cb5fc50220969b0a4e1058
- https://git.kernel.org/stable/c/1b54faa5f47fa7c642179744aeff03f0810dc62e
- https://git.kernel.org/stable/c/3ba402610843d7d15c7f3966a461deeeaff7fba4
- https://git.kernel.org/stable/c/6871a676aa534e8f218279672e0445c725f81026
- https://git.kernel.org/stable/c/bd496a44f041da9ef3afe14d1d6193d460424e91
- https://git.kernel.org/stable/c/d83b0c03ef8fbea2f03029a1cc1f5041f0e1d47f
- https://git.kernel.org/stable/c/e6bba328578feb58c614c11868c259b40484c5fa
- https://git.kernel.org/stable/c/fe4a4fc179b7898055555a11685915473588392e
- https://git.kernel.org/stable/c/ff9d61db59bb27d16d3f872bff2620d50856b80c
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.3