CVE-2025-21918

MEDIUM

Linux Kernel 5.16-6.13.6 - NULL Pointer Dereference in UCSI Type-C Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Fix NULL pointer access Resources should be released only after all threads that utilize them have been destroyed. This commit ensures that resources are not released prematurely by waiting for the associated workqueue to complete before deallocating them.

Scores

CVSS v3 5.5
EPSS 0.0018
EPSS Percentile 7.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (18)
linux/Kernel 5.16.0 - 6.1.133linux
linux/Kernel 6.13.0 - 6.13.7linux
linux/Kernel 6.2.0 - 6.6.83linux
linux/Kernel 6.7.0 - 6.12.19linux
Linux/Linux < 5.16
Linux/Linux 5.16
Linux/Linux 6.1.133 - 6.1.*
Linux/Linux 6.12.19 - 6.12.*
Linux/Linux 6.13.7 - 6.13.*
Linux/Linux 6.14
... and 8 more
Published Apr 01, 2025
Tracked Since Feb 18, 2026