CVE-2025-37994 – “Linux Kernel USB TypeC UCSI NULL Pointer Access Vulnerability”

The following table lists the changes that have been made to the
CVE-2025-37994 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    May. 29, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    usb: typec: ucsi: displayport: Fix NULL pointer access

    This patch ensures that the UCSI driver waits for all pending tasks in the
    ucsi_displayport_work workqueue to finish executing before proceeding with
    the partner removal.

    Added Reference https://git.kernel.org/stable/c/076ab0631ed4928905736f1701e25f1e722bc086
    Added Reference https://git.kernel.org/stable/c/14f298c52188c34acde9760bf5abc669c5c36fdb
    Added Reference https://git.kernel.org/stable/c/312d79669e71283d05c05cc49a1a31e59e3d9e0e
    Added Reference https://git.kernel.org/stable/c/5ad298d6d4aebe1229adba6427e417e89a5208d8
    Added Reference https://git.kernel.org/stable/c/7804c4d63edfdd5105926cc291e806e8f4ce01b5
    Added Reference https://git.kernel.org/stable/c/e9b63faf5c97deb43fc39a52edbc39d626cc14bf
Share the Post:

Related Posts