Executive Summary

Informations
Name CVE-2025-21685 First vendor Publication 2025-02-09
Vendor Cve Last vendor Modification 2025-02-11

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 4.7
Base Score 4.7 Environmental Score 4.7
impact SubScore 3.6 Temporal Score 4.7
Exploitabality Sub Score 1
 
Attack Vector Local Attack Complexity High
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev race

The yt2_1380_fc_serdev_probe() function calls devm_serdev_device_open() before setting the client ops via serdev_device_set_client_ops(). This ordering can trigger a NULL pointer dereference in the serdev controller's receive_buf handler, as it assumes serdev->ops is valid when SERPORT_ACTIVE is set.

This is similar to the issue fixed in commit 5e700b384ec1 ("platform/chrome: cros_ec_uart: properly fix race condition") where devm_serdev_device_open() was called before fully initializing the device.

Fix the race by ensuring client ops are set before enabling the port via devm_serdev_device_open().

Note, serdev_device_set_baudrate() and serdev_device_set_flow_control() calls should be after the devm_serdev_device_open() call.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21685

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-476 NULL Pointer Dereference

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3699

Sources (Detail)

https://git.kernel.org/stable/c/3f67e07873df3c6d9ce2582260b83732e1d3a40b
https://git.kernel.org/stable/c/59616a91e5e74833b2008b56c66879857c616006
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
Date Informations
2025-03-29 03:46:24
  • Multiple Updates
2025-03-28 13:48:52
  • Multiple Updates
2025-03-28 03:24:10
  • Multiple Updates
2025-03-25 03:30:03
  • Multiple Updates
2025-03-19 03:18:38
  • Multiple Updates
2025-03-18 03:31:36
  • Multiple Updates
2025-03-14 03:18:38
  • Multiple Updates
2025-03-06 14:15:10
  • Multiple Updates
2025-03-06 03:09:32
  • Multiple Updates
2025-02-22 03:28:46
  • Multiple Updates
2025-02-11 21:20:37
  • Multiple Updates
2025-02-09 17:20:27
  • First insertion