PT-2025-34416 · Linux+4 · Linux Kernel+4
Published
2025-06-24
·
Updated
2025-12-15
·
CVE-2025-38655
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A NULL pointer dereference issue was resolved in the pinctrl subsystem for Canaan K230 devices. The vulnerability occurs when retrieving the "pinmux" property from the device tree node, specifically if the property is missing. A missing check for the return value of
of get property() could lead to a crash. Additionally, a typo in the device ID match table comment was corrected from "sintenel" to "sentinel".Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Canaan K230
Linuxmint
Linux Kernel
Ubuntu