CVE-2025-38381

medium

Description

In the Linux kernel, the following vulnerability has been resolved: Input: cs40l50-vibra - fix potential NULL dereference in cs40l50_upload_owt() The cs40l50_upload_owt() function allocates memory via kmalloc() without checking for allocation failure, which could lead to a NULL pointer dereference. Return -ENOMEM in case allocation fails.

References

https://git.kernel.org/stable/c/ea20568895c1122f15b6fc9e8d02c6cbe22964f8

https://git.kernel.org/stable/c/e87fc697fa4be5164e47cfba4ddd4732499adc60

https://git.kernel.org/stable/c/4cf65845fdd09d711fc7546d60c9abe010956922

Details

Source: Mitre, NVD

Published: 2025-07-25

Updated: 2025-07-25

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00017