CVE-2025-22006

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
03/04/2025
Last modified:
01/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: ethernet: ti: am65-cpsw: Fix NAPI registration sequence<br /> <br /> Registering the interrupts for TX or RX DMA Channels prior to registering<br /> their respective NAPI callbacks can result in a NULL pointer dereference.<br /> This is seen in practice as a random occurrence since it depends on the<br /> randomness associated with the generation of traffic by Linux and the<br /> reception of traffic from the wire.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.12.14 (including) 6.12.21 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13.3 (including) 6.13.9 (excluding)