CVE-2025-21798

MEDIUM

Linux Kernel - Null Pointer Dereference in Firewire KUnit Test

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: firewire: test: Fix potential null dereference in firewire kunit test kunit_kzalloc() may return a NULL pointer, dereferencing it without NULL check may lead to NULL dereference. Add a NULL check for test_state.

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 9.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (11)
linux/Kernel 6.13.0 - 6.13.2linux
linux/Kernel 6.8.0 - 6.12.13linux
Linux/Linux < 6.8
Linux/Linux 1c8506d62624fbc57db75414a387f365da8422e9 - 352fafe97784e81a10a7c74bd508f71a19b53c2a
Linux/Linux 1c8506d62624fbc57db75414a387f365da8422e9 - 70fcb25472d90dd3b87cbee74b9eb68670b0c7b8
Linux/Linux 1c8506d62624fbc57db75414a387f365da8422e9 - c6896bf4c611c3dd126f3e03685f2360a18b3d6f
Linux/Linux 6.12.13 - 6.12.*
Linux/Linux 6.13.2 - 6.13.*
Linux/Linux 6.14
Linux/Linux 6.8
... and 1 more
Published Feb 27, 2025
Tracked Since Feb 18, 2026