Linux Kernel Null Pointer Dereference Vulnerability in MHI Bus Endpoint Handling

Vulnerability

A null pointer dereference vulnerability has been identified in the Linux kernel's Mobile Hotspot Interface (MHI) bus endpoint management. This issue arises because the channel disconnect status, -ENOTCONN, is sent even when the client driver is not available, leading to a null pointer dereference. The vulnerability is present in the stable versions of the Linux kernel.

Impact

Exploitation of this vulnerability causes a null pointer dereference, which can lead to a system crash or instability.

Reproduction

The vulnerability can be reproduced by sending STOP or RESET commands to an MHI endpoint when the client driver is not available. This will trigger the channel disconnect status -ENOTCONN, causing a null pointer dereference.

Remediation

Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed.

Added: Dec 30, 2025, 3:05 PM
Updated: Dec 30, 2025, 3:05 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
1.6
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.