CVE-2025-21773: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: fix potential NULL pointer dereference on udev->serial The driver assumed that es58x_dev->udev->serial could never be NULL. While this is true on commercially available devices, an attacker could spoof the device identity providing a NULL USB serial number. That would trigger a NULL pointer dereference. Add a check on es58x_dev->udev->serial before accessing it.
Affected products
- Linux Linux Kernel: from 6.2, before 6.6.79 (fixed in 6.6.79); from 6.7, before 6.12.16 (fixed in 6.12.16); from 6.13, before 6.13.4 (fixed in 6.13.4); version 6.14 only
Published 2025-02-27. Last modified 2026-06-17.