CVE-2025-37972
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/05/2025
Last modified:
21/05/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Input: mtk-pmic-keys - fix possible null pointer dereference<br />
<br />
In mtk_pmic_keys_probe, the regs parameter is only set if the button is<br />
parsed in the device tree. However, on hardware where the button is left<br />
floating, that node will most likely be removed not to enable that<br />
input. In that case the code will try to dereference a null pointer.<br />
<br />
Let&#39;s use the regs struct instead as it is defined for all supported<br />
platforms. Note that it is ok setting the key reg even if that latter is<br />
disabled as the interrupt won&#39;t be enabled anyway.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/09429ddb5a91e9e8f72cd18c012ec4171c2f85ec
- https://git.kernel.org/stable/c/11cdb506d0fbf5ac05bf55f5afcb3a215c316490
- https://git.kernel.org/stable/c/334d74a798463ceec02a41eb0e2354aaac0d6249
- https://git.kernel.org/stable/c/619c05fb176c272ac6cecf723446b39723ee6d97
- https://git.kernel.org/stable/c/90fa6015ff83ef1c373cc61b7c924ab2bcbe1801