cbcvebase.
CVE-2025-21982
published 2025-04-01

CVE-2025-21982: In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: npcm8xx: Add NULL check in npcm8xx_gpio_fw devm_kasprintf() calls can…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: npcm8xx: Add NULL check in npcm8xx_gpio_fw devm_kasprintf() calls can return null pointers on failure. But the return values were not checked in npcm8xx_gpio_fw(). Add NULL check in npcm8xx_gpio_fw(), to handle kernel NULL pointer dereference error.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.20-1 (forky)linux 6.12.20-1 (forky)
linuxlinux
linuxlinux>= acf4884a571709cad99f98aabe08b7cacd62dc80 < a585f6ea42ec259a9a57e3e2580fa527c92187d0a585f6ea42ec259a9a57e3e2580fa527c92187d0
linuxlinux>= acf4884a571709cad99f98aabe08b7cacd62dc80 < 6a08a86e5aff8e65368ccd463348fdda261008216a08a86e5aff8e65368ccd463348fdda26100821
linuxlinux>= acf4884a571709cad99f98aabe08b7cacd62dc80 < acf40ab42799e4ae1397ee6f5c5941092d66f999acf40ab42799e4ae1397ee6f5c5941092d66f999
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 6.13 < 6.13.86.13.8
linuxlinux_kernel>= 6.7 < 6.12.206.12.20

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.