Fiche vulnérabilité
CVE-2025-37748 : faille moyenne linux linux kernel (CVSS 5.5)
Description
In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group Currently, mtk_iommu calls during probe iommu_device_register before the hw_list from driver data is initialized. Since iommu probing issue fix, it leads to NULL pointer dereference in mtk_iommu_device_group when hw_list is accessed with list_first_entry (not null safe). So, change the call order to ensure iommu_device_register is called after the driver data are initialized.
En bref
- Sévérité
- Moyenne (CVSS 5.5)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 1 mai 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- linux linux kernel
- debian debian linux
Références
- Fiche CVE-2025-37748 sur le NVD (NIST)
- git.kernel.org/stable/c/2f75cb27bef43c8692b0f5e471e5632f6a9be…
- git.kernel.org/stable/c/38e8844005e6068f336a3ad45451a562a0040…
- git.kernel.org/stable/c/69f9d2d37d1207c5a73dac52a4ce1361ead70…
- git.kernel.org/stable/c/6abd09bed43b8d83d461e0fb5b9a200a06aa8…
- git.kernel.org/stable/c/a0842539e8ef9386c070156103aff888e558a…
- git.kernel.org/stable/c/ce7d3b2f6f393fa35f0ea12861b83a1ca28b2…
- lists.debian.org/debian-lts-announce/2025/05/msg00045.html