PT-2025-17273 · Linux+5 · Linux Kernel+5
Published
2025-03-12
·
Updated
2026-04-20
·
CVE-2025-38240
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved. The issue is related to the function
mtk dp wait hpd asserted(), which may be called before the mtk dp->drm dev pointer is assigned, potentially causing a NULL pointer dereference. This can occur via a specific callpath involving mtk edp wait hpd asserted, panel probe, and dp aux ep probe. The error messages in mtk dp wait hpd asserted() and mtk dp parse capabilities() have been changed to dev err() to avoid this issue. The error code has also been added to these messages to facilitate future debugging.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu