CVE-2025-37994: usb: typec: ucsi: displayport: Fix NULL pointer access
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: displayport: Fix NULL pointer access
This patch ensures that the UCSI driver waits for all pending tasks in the ucsidisplayportwork workqueue to finish executing before proceeding with the partner removal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37994?
CVE-2025-37994 has been classified with a severity level of medium due to the potential for NULL pointer dereference in the UCSI driver.
How do I fix CVE-2025-37994?
To fix CVE-2025-37994, it is recommended to upgrade to the latest version of the Linux kernel where the vulnerability has been patched.
What systems are affected by CVE-2025-37994?
CVE-2025-37994 affects the Linux kernel, particularly systems utilizing the UCSI driver for USB-C functionality.
What are the potential impacts of CVE-2025-37994?
The potential impact of CVE-2025-37994 includes system crashes or unresponsive states due to NULL pointer access in the UCSI driver.
When was CVE-2025-37994 reported?
CVE-2025-37994 was reported in 2025 and has been addressed with a patch in the subsequent Linux kernel releases.