PT-2025-33757 · Linux+3 · Linux Kernel+3
Published
2025-07-18
·
Updated
2025-12-15
·
CVE-2025-38558
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
A NULL pointer dereference issue was identified in the USB gadget driver's UVC (USB Video Class) handling of frame-based formats. Specifically, the color matching descriptor was not initialized, leading to a potential crash when userspace configuration does not explicitly define it. This occurs during the processing of uncompressed and MJPEG formats.
Recommendations:
Linux kernel versions prior to 6.6.58 are affected. Update to version 6.6.58 or later to resolve this issue.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Ubuntu