CVE-2026-31549
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
5.5 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved:
i2c: cp2615: fix serial string NULL-deref at probe
The cp2615 driver uses the USB device serial string as the i2c adapter
name but does not make sure that the string exists.
Verify that the device has a serial number before accessing it to avoid
triggering a NULL-pointer dereference (e.g. with malicious devices).
i2c: cp2615: fix serial string NULL-deref at probe
The cp2615 driver uses the USB device serial string as the i2c adapter
name but does not make sure that the string exists.
Verify that the device has a serial number before accessing it to avoid
triggering a NULL-pointer dereference (e.g. with malicious devices).
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-476
Source
NVD
Vendor
Linux
Product
Linux
External References
- https://git.kernel.org/stable/c/13ccf9b106bba121728f1625c4375a1bd8f5c5a3
- https://git.kernel.org/stable/c/4a22af879172336370ae3e81e7f65fb2f69472ee
- https://git.kernel.org/stable/c/69aece634a7eebafd9a596e5494d52facf6f26ec
- https://git.kernel.org/stable/c/a9778298f47036866ea15eeb17242e8a4612580f
- https://git.kernel.org/stable/c/aa79f996eb41e95aed85a1bd7f56bcd6a3842008
- https://git.kernel.org/stable/c/e68c267787778bcdf3d91b06f794faaba7f0d1d1
- https://git.kernel.org/stable/c/efe996bcfe50c2dcc6cf65c574285713b722ced7
Discussion (0)
Add Comment
No comments yet. Be the first!