PT-2025-33757 · Linux+3 · Linux Kernel+3

Published

2025-07-18

·

Updated

2025-12-15

·

CVE-2025-38558

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.58
Description: A NULL pointer dereference issue was identified in the USB gadget driver's UVC (USB Video Class) handling of frame-based formats. Specifically, the color matching descriptor was not initialized, leading to a potential crash when userspace configuration does not explicitly define it. This occurs during the processing of uncompressed and MJPEG formats.
Recommendations: Linux kernel versions prior to 6.6.58 are affected. Update to version 6.6.58 or later to resolve this issue.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10731
CVE-2025-38558
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7934-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu