cbcvebase.
CVE-2025-21918
published 2025-04-01

CVE-2025-21918: In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Fix NULL pointer access Resources should be released only after all…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.4th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Fix NULL pointer access Resources should be released only after all threads that utilize them have been destroyed. This commit ensures that resources are not released prematurely by waiting for the associated workqueue to complete before deallocating them.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= b9aa02ca39a49740926c2c450a1505a4a0f8954a < 7a735a8a46f6ebf898bbefd96659ca5da798bce07a735a8a46f6ebf898bbefd96659ca5da798bce0
linuxlinux>= b9aa02ca39a49740926c2c450a1505a4a0f8954a < 46fba7be161bb89068958138ea64ec33c0b446d446fba7be161bb89068958138ea64ec33c0b446d4
linuxlinux>= b9aa02ca39a49740926c2c450a1505a4a0f8954a < 079a3e52f3e751bb8f5937195bdf25c5d14fdff0079a3e52f3e751bb8f5937195bdf25c5d14fdff0
linuxlinux>= b9aa02ca39a49740926c2c450a1505a4a0f8954a < 592a0327d026a122e97e8e8bb7c60cbbe7697344592a0327d026a122e97e8e8bb7c60cbbe7697344
linuxlinux>= b9aa02ca39a49740926c2c450a1505a4a0f8954a < b13abcb7ddd8d38de769486db5bd917537b32ab1b13abcb7ddd8d38de769486db5bd917537b32ab1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.16 < 6.1.1336.1.133
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83
linuxlinux_kernel>= 6.7 < 6.12.196.12.19
msrcazl3_kernel_6.6.82.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.85.1-2_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.