CVE-2025-22052

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix Oops after disconnect in ni_usb If the usb dongle is disconnected subsequent calls to the driver cause a NULL dereference Oops as the bus_interface is set to NULL on disconnect. This problem was introduced by setting usb_dev from the bus_interface for dev_xxx messages. Previously bus_interface was checked for NULL only in the the functions directly calling usb_fill_bulk_urb or usb_control_msg. Check for valid bus_interface on all interface entry points and return -ENODEV if it is NULL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

29 Apr 2025, 18:50

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: staging: gpib: Se corrige el error "Oops" tras la desconexión en ni_usb. Si la llave USB se desconecta, las llamadas posteriores al controlador provocan una desreferencia "Oops" a NULL, ya que bus_interface se establece en NULL al desconectarse. Este problema se introdujo al configurar "usb_dev" desde bus_interface para los mensajes "dev_xxx". Anteriormente, bus_interface solo se verificaba para NULL en las funciones que llamaban directamente a usb_fill_bulk_urb o usb_control_msg. Compruebe si bus_interface es válido en todos los puntos de entrada de la interfaz y devuelva -ENODEV si es NULL.
CWE CWE-476
References () https://git.kernel.org/stable/c/5dc98ba6f7304c188b267ef481281849638447bf - () https://git.kernel.org/stable/c/5dc98ba6f7304c188b267ef481281849638447bf - Patch
References () https://git.kernel.org/stable/c/a239c6e91b665f1837cf57b97fe638ef1baf2e78 - () https://git.kernel.org/stable/c/a239c6e91b665f1837cf57b97fe638ef1baf2e78 - Patch
References () https://git.kernel.org/stable/c/b2d8d7959077c5d4b11d0dc6bd2167791fd1c72e - () https://git.kernel.org/stable/c/b2d8d7959077c5d4b11d0dc6bd2167791fd1c72e - Patch

16 Apr 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-16 15:15

Updated : 2025-04-29 18:50


NVD link : CVE-2025-22052

Mitre link : CVE-2025-22052

CVE.ORG link : CVE-2025-22052


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference