cbcvebase.
CVE-2025-22054
published 2025-04-16

CVE-2025-22054: In the Linux kernel, the following vulnerability has been resolved: arcnet: Add NULL check in com20020pci_probe() devm_kasprintf() returns NULL when memory…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.1th percentile
In the Linux kernel, the following vulnerability has been resolved: arcnet: Add NULL check in com20020pci_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, com20020pci_probe() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue and ensure no resources are left allocated.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 4.19.302 < 4.204.20
linuxlinux>= 5.10.204 < 5.10.2365.10.236
linuxlinux>= 5.15.143 < 5.15.1805.15.180
linuxlinux>= 5.4.264 < 5.4.2925.4.292
linuxlinux>= 5106d7adb74bc6160806b45ffd2321b10ca14ee0 < ececf8eff6c25acc239fa8f0fd837c76bc770547ececf8eff6c25acc239fa8f0fd837c76bc770547
linuxlinux>= 6.1.68 < 6.1.1346.1.134
linuxlinux>= 6.6.7 < 6.6.876.6.87
linuxlinux>= 6b17a597fc2f13aaaa0a2780eb7edb9ae7ac9aea < ebebeb58d48e25525fa654f2c53a24713fe141c3ebebeb58d48e25525fa654f2c53a24713fe141c3
linuxlinux>= 6b17a597fc2f13aaaa0a2780eb7edb9ae7ac9aea < a654f31b33515d39bb56c75fd8b26bef025ced7ea654f31b33515d39bb56c75fd8b26bef025ced7e
linuxlinux>= 6b17a597fc2f13aaaa0a2780eb7edb9ae7ac9aea < 887226163504494ea7e58033a97c2d2ab12e05d4887226163504494ea7e58033a97c2d2ab12e05d4
linuxlinux>= 6b17a597fc2f13aaaa0a2780eb7edb9ae7ac9aea < fda8c491db2a90ff3e6fbbae58e495b4ddddeca3fda8c491db2a90ff3e6fbbae58e495b4ddddeca3
linuxlinux>= 75c53a4c43295fb8b09edae45239790db9cc69c3 < ef8b29398ea6061ac8257f3e45c9be45cc004ce2ef8b29398ea6061ac8257f3e45c9be45cc004ce2
linuxlinux>= 8d034da82563a526dbd7e9069bb3f6946403b72c < be8a0decd0b59a52a07276f9ef3b33ef820b2179be8a0decd0b59a52a07276f9ef3b33ef820b2179
linuxlinux>= d54f5a5bc85afd01b0a00689b795e31db54adc15 < 905a34dc1ad9a53a8aaaf8a759ea5dbaaa30418d905a34dc1ad9a53a8aaaf8a759ea5dbaaa30418d
linuxlinux>= e38cd53421ed4e37fc99662a0f2a0c567993844f < 661cf5d102949898c931e81fd4e1c773afcdeafa661cf5d102949898c931e81fd4e1c773afcdeafa
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.