SB2025022794 - NULL pointer dereference in Linux kernel can rockchip driver
Published: February 27, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-21774)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the rkcanfd_handle_rx_fifo_overflow_int() function in drivers/net/can/rockchip/rockchip_canfd-core.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/118fb35681bd2c0d2afa22f7be0ef94bb4d06849
- https://git.kernel.org/stable/c/946750e7865df2e70045071051abf768785dd570
- https://git.kernel.org/stable/c/f7f0adfe64de08803990dc4cbecd2849c04e314a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14