CVE-2025-37748
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
01/05/2025
Last modified:
04/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
iommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group<br />
<br />
Currently, mtk_iommu calls during probe iommu_device_register before<br />
the hw_list from driver data is initialized. Since iommu probing issue<br />
fix, it leads to NULL pointer dereference in mtk_iommu_device_group when<br />
hw_list is accessed with list_first_entry (not null safe).<br />
<br />
So, change the call order to ensure iommu_device_register is called<br />
after the driver data are initialized.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.19 (including) | 6.1.135 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.88 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.13.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.14 (including) | 6.14.3 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2f75cb27bef43c8692b0f5e471e5632f6a9beb99
- https://git.kernel.org/stable/c/38e8844005e6068f336a3ad45451a562a0040ca1
- https://git.kernel.org/stable/c/69f9d2d37d1207c5a73dac52a4ce1361ead707f5
- https://git.kernel.org/stable/c/6abd09bed43b8d83d461e0fb5b9a200a06aa8a27
- https://git.kernel.org/stable/c/a0842539e8ef9386c070156103aff888e558a60c
- https://git.kernel.org/stable/c/ce7d3b2f6f393fa35f0ea12861b83a1ca28b295c
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html



