cbcvebase.
CVE-2025-22066
published 2025-04-16

CVE-2025-22066: In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NULL when…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, imx_card_probe() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= aa736700f42fa0813e286ca2f9274ffaa25163b9 < 018e6cf2503e60087747b0ebc190e18b3640766f018e6cf2503e60087747b0ebc190e18b3640766f
linuxlinux>= aa736700f42fa0813e286ca2f9274ffaa25163b9 < 38253922a89a742e7e622f626b41c6438836736138253922a89a742e7e622f626b41c64388367361
linuxlinux>= aa736700f42fa0813e286ca2f9274ffaa25163b9 < e283a5bf4337a7300ac5e6ae363cc8b242a0b4b7e283a5bf4337a7300ac5e6ae363cc8b242a0b4b7
linuxlinux>= aa736700f42fa0813e286ca2f9274ffaa25163b9 < 4d8458e48ff135bddc402ad79821dc058ea163d04d8458e48ff135bddc402ad79821dc058ea163d0
linuxlinux>= aa736700f42fa0813e286ca2f9274ffaa25163b9 < b01700e08be99e3842570142ec5973ccd7e73eafb01700e08be99e3842570142ec5973ccd7e73eaf
linuxlinux>= aa736700f42fa0813e286ca2f9274ffaa25163b9 < dd2bbb9564d0d24a2643ad90008a79840368c4b4dd2bbb9564d0d24a2643ad90008a79840368c4b4
linuxlinux>= aa736700f42fa0813e286ca2f9274ffaa25163b9 < 93d34608fd162f725172e780b1c60cc93a92071993d34608fd162f725172e780b1c60cc93a920719
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.14 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1346.1.134
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.2 < 6.6.876.6.87
linuxlinux_kernel>= 6.7 < 6.12.236.12.23
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.