CVE-2025-38363

medium

Description

In the Linux kernel, the following vulnerability has been resolved: drm/tegra: Fix a possible null pointer dereference In tegra_crtc_reset(), new memory is allocated with kzalloc(), but no check is performed. Before calling __drm_atomic_helper_crtc_reset, state should be checked to prevent possible null pointer dereference.

References

https://git.kernel.org/stable/c/c7fc459ae6f988e0d5045a270bd600ab08bc61f1

https://git.kernel.org/stable/c/ac4ca634f0c9f227538711d725339293f7047b02

https://git.kernel.org/stable/c/ab390ab81241cf8bf37c0a0ac2e9c6606bf3e991

https://git.kernel.org/stable/c/99a25fc7933b88d5e16668bf6ba2d098e1754406

https://git.kernel.org/stable/c/780351a5f61416ed2ba1199cc57e4a076fca644d

https://git.kernel.org/stable/c/5ff3636bcc32e1cb747f6f820bcf2bb6990a7d41

https://git.kernel.org/stable/c/31ac2c680a8ac11dc54a5b339a07e138bcedd924

Details

Source: Mitre, NVD

Published: 2025-07-25

Updated: 2025-07-25

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00024