Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2025-38143— backlight: pm8941: Add NULL check in wled_configure()

EPSS 0.14% · P34

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinuxf86b77583d88c8402e8d89a339d96f847318f8a8< 6a56446595730a5e3f06a30902e23cb037d28146affected
f86b77583d88c8402e8d89a339d96f847318f8a8< 9d06ac32c202142da40904180f2669ed4f5073acaffected
f86b77583d88c8402e8d89a339d96f847318f8a8< 21528806560510458378ea52c37e35b0773afaeaaffected
f86b77583d88c8402e8d89a339d96f847318f8a8< fde314445332015273c8f51d2659885c606fe135affected
f86b77583d88c8402e8d89a339d96f847318f8a8< 1be2000b703b02e149f8f2061054489f6c18c972affected
f86b77583d88c8402e8d89a339d96f847318f8a8< 4a715be3fe80b68fa55cb3569af3d294be101626affected
f86b77583d88c8402e8d89a339d96f847318f8a8< e12d3e1624a02706cdd3628bbf5668827214fa33affected
5.0affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-38143

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
backlight: pm8941: Add NULL check in wled_configure()
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: backlight: pm8941: Add NULL check in wled_configure() devm_kasprintf() returns NULL when memory allocation fails. Currently, wled_configure() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查devm_kasprintf返回值,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux f86b77583d88c8402e8d89a339d96f847318f8a8 ~ 6a56446595730a5e3f06a30902e23cb037d28146 -
LinuxLinux 5.0 -

II. Public POCs for CVE-2025-38143

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38143

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-07-03 · 78 CVEs total

CVE-2025-38128Bluetooth: MGMT: reject malformed HCI_CMD_SYNC commands
CVE-2025-38126net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping
CVE-2025-38113ACPI: CPPC: Fix NULL pointer dereference when nosmp is used
CVE-2025-38125net: stmmac: make sure that ptp_rate is not 0 before configuring EST
CVE-2025-38124net: fix udp gso skb_segment after pull from frag_list
CVE-2025-38127ice: fix Tx scheduler error handling in XDP callback
CVE-2025-38129page_pool: Fix use-after-free in page_pool_recycle_in_ring
CVE-2025-38130drm/connector: only call HDMI audio helper plugged cb if non-null
CVE-2025-38131coresight: prevent deactivate active config while enabling the config
CVE-2025-38132coresight: holding cscfg_csdev_lock while removing cscfg from csdev
CVE-2025-38122gve: add missing NULL check for gve_alloc_pending_packet() in TX DQO
CVE-2025-38123net: wwan: t7xx: Fix napi rx poll issue
CVE-2025-38121wifi: iwlwifi: mld: avoid panic on init failure
CVE-2025-38119scsi: core: ufs: Fix a hang in the error handler
CVE-2025-38120netfilter: nf_set_pipapo_avx2: fix initial map fill
CVE-2025-38118Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete
CVE-2025-38117Bluetooth: MGMT: Protect mgmt_pending list with its own lock
CVE-2025-38115net_sched: sch_sfq: fix a potential crash on gso_skb handling
CVE-2025-38116wifi: ath12k: fix uaf in ath12k_core_init()
CVE-2025-38114e1000: Move cancel_work_sync to avoid deadlock

Showing top 20 of 78 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38143

No comments yet


Leave a comment