Linux Kernel Null Pointer Dereference Vulnerability in USB PHY Sunplus Driver

Vulnerability

A null pointer dereference vulnerability has been identified in the USB PHY Sunplus driver of the Linux kernel. The issue arises in the function 'sp_usb_phy_probe()', which calls 'platform_get_resource_byname()'. If this call fails, it returns NULL, leading to a potential null pointer dereference when 'devm_ioremap()' uses 'usbphy->moon4_res_mem->start' as input. The vulnerability can be exploited by checking the return value of 'platform_get_resource_byname()' to prevent the null pointer dereference.

Impact

Exploitation of this vulnerability can lead to a null pointer dereference, causing a kernel crash.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.