cbcvebase.
CVE-2025-37881
published 2025-05-09

CVE-2025-37881: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.2th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name, returned by devm_kasprintf(), could be NULL. A pointer check is added to prevent potential NULL pointer dereference. This is similar to the fix in commit 3027e7b15b02 ("ice: Fix some null pointer dereference issues in ice_ptp.c"). This issue is found by our static analysis tool

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= 7ecca2a4080cb6b1fa174adc588fce9e9014c43c < a777ccfb9ba8d43f745e41b69ba39d4a506a081ea777ccfb9ba8d43f745e41b69ba39d4a506a081e
linuxlinux>= 7ecca2a4080cb6b1fa174adc588fce9e9014c43c < c8d4faf452a627f9b09c3a5c366133a19e5b7a28c8d4faf452a627f9b09c3a5c366133a19e5b7a28
linuxlinux>= 7ecca2a4080cb6b1fa174adc588fce9e9014c43c < d26a6093d52904cacdbb75424c323c19b443a890d26a6093d52904cacdbb75424c323c19b443a890
linuxlinux>= 7ecca2a4080cb6b1fa174adc588fce9e9014c43c < 36d68151712e525450f0fbb3045e7110f0d9b61036d68151712e525450f0fbb3045e7110f0d9b610
linuxlinux>= 7ecca2a4080cb6b1fa174adc588fce9e9014c43c < cfa7984f69359761b07a7831c1258c0fde1e0389cfa7984f69359761b07a7831c1258c0fde1e0389
linuxlinux>= 7ecca2a4080cb6b1fa174adc588fce9e9014c43c < 052fb65335befeae8500e88d69ea022266baaf6d052fb65335befeae8500e88d69ea022266baaf6d
linuxlinux>= 7ecca2a4080cb6b1fa174adc588fce9e9014c43c < 61006ca381b4d65d2b8ca695ea8da1ce18d6dee361006ca381b4d65d2b8ca695ea8da1ce18d6dee3
linuxlinux>= 7ecca2a4080cb6b1fa174adc588fce9e9014c43c < 8c75f3e6a433d92084ad4e78b029ae680865420f8c75f3e6a433d92084ad4e78b029ae680865420f
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.18 < 5.4.2935.4.293
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1366.1.136
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.14.56.14.5
linuxlinux_kernel>= 6.2 < 6.6.896.6.89

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.