Linux Kernel etas_es58x Driver NULL Pointer Dereference Vulnerability

Vulnerability

A NULL pointer dereference vulnerability has been identified in the Linux kernel's etas_es58x driver. The issue arises because the driver incorrectly assumed that the USB serial number would never be NULL. While this assumption holds true for commercially available devices, an attacker could potentially spoof the device identity to provide a NULL serial number, leading to a NULL pointer dereference. The vulnerability has been addressed by adding a check for the serial number before accessing it.

Impact

Exploitation of this vulnerability could lead to a system crash or undefined behavior due to the NULL pointer dereference.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.