CVE-2025-22054: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: arcnet: Add NULL check in com20020pci_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, com20020pci_probe() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue and ensure no resources are left allocated.

Affected products

  • Linux Linux Kernel: from 4.19.302, before 4.20 (fixed in 4.20); from 5.4.264, before 5.4.292 (fixed in 5.4.292); from 5.10.204, before 5.10.236 (fixed in 5.10.236); from 5.15.143, before 5.15.180 (fixed in 5.15.180); from 6.1.68, before 6.1.134 (fixed in 6.1.134); from 6.6.7, before 6.6.87 (fixed in 6.6.87); …

Published 2025-04-16. Last modified 2026-06-17.