cbcvebase.
CVE-2025-37784
published 2025-05-01

CVE-2025-37784: In the Linux kernel, the following vulnerability has been resolved: net: ti: icss-iep: Fix possible NULL pointer dereference for perout request The ICSS IEP…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
6.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ti: icss-iep: Fix possible NULL pointer dereference for perout request The ICSS IEP driver tracks perout and pps enable state with flags. Currently when disabling pps and perout signals during icss_iep_exit(), results in NULL pointer dereference for perout. To fix the null pointer dereference issue, the icss_iep_perout_enable_hw function can be modified to directly clear the IEP CMP registers when disabling PPS or PEROUT, without referencing the ptp_perout_request structure, as its contents are irrelevant in this case.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.25-1 (forky)linux 6.12.25-1 (forky)
linuxlinux
linuxlinux>= 4ac8e8bf70b436294534d06e5d500e950e20c13d < da5035d7aeadcfa44096dd34689bfed6c657f559da5035d7aeadcfa44096dd34689bfed6c657f559
linuxlinux>= 6.12.9 < 6.12.256.12.25
linuxlinux>= 6.6.70 < 6.6.886.6.88
linuxlinux>= 9b115361248dc6cce182a2dc030c1c70b0a9639e < eeec66327001421531b3fb1a2ac32efc8a2493b0eeec66327001421531b3fb1a2ac32efc8a2493b0
linuxlinux>= 9b115361248dc6cce182a2dc030c1c70b0a9639e < 7349c9e9979333abfce42da5f9025598083b59c97349c9e9979333abfce42da5f9025598083b59c9
linuxlinux>= d6b130fabfe197935346fe9f1e50a0947b2b1be7 < 7891619d21f07a88e0275d6d43db74035aa74f697891619d21f07a88e0275d6d43db74035aa74f69
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.12.9 < 6.12.256.12.25
linuxlinux_kernel>= 6.13.1 < 6.14.46.14.4
linuxlinux_kernel>= 6.6.70 < 6.6.886.6.88
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.