Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2025-38275

Description

In the Linux kernel, the following vulnerability has been resolved:phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bugThe qmp_usb_iomap() helper function currently returns the raw result ofdevm_ioremap() for non-exclusive mappings. Since devm_ioremap() may returna NULL pointer and the caller only checks error pointers with IS_ERR(),NULL could bypass the check and lead to an invalid dereference.Fix the issue by checking if devm_ioremap() returns NULL. When it does,qmp_usb_iomap() now returns an error pointer via IOMEM_ERR_PTR(-ENOMEM),ensuring safe and consistent error handling.

POC

Reference

No PoCs from references.

Github

- https://github.com/w4zu/Debian_security