Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A null pointer dereference vulnerability has been identified in the USB PHY Sunplus driver of the Linux kernel. The issue arises in the function 'sp_usb_phy_probe()', which calls 'platform_get_resource_byname()'. If this call fails, it returns NULL, leading to a potential null pointer dereference when 'devm_ioremap()' uses 'usbphy->moon4_res_mem->start' as input. The vulnerability can be exploited by checking the return value of 'platform_get_resource_byname()' to prevent the null pointer dereference.
Exploitation of this vulnerability can lead to a null pointer dereference, causing a kernel crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.