CVE-2025-22009

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 8, 2025
Updated: Apr 10, 2025
CWE ID 476

Summary

CVE-2025-22009 is a Linux kernel vulnerability that results in a NULL pointer dereference during boot time. This issue occurs in the 'regulator: dummy: force synchronous probing' functionality, specifically in the 'kobject_get()' function call. The vulnerability arises due to incomplete probing of the 'dummy' regulator driver, causing 'dummy_regulator_rdev' to be NULL. This problem can lead to kernel instability and potentially allow unauthorized access or system crashes. The vulnerability can be exploited by different kernel threads (kworker/u4:*), and further investigation is required to assess the potential impact and possible mitigations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share