In the Linux kernel, the following vulnerability has been resolved:
ARM: davinci: da850-evm: Avoid NULL pointer dereference
With newer versions of GCC, there is a panic in da850_evm_config_emac() when booting multi_v5_defconfig in QEMU under the palmetto-bmc machine:
Unable to handle kernel NULL pointer dereference at virtual address 00000020 pgd = (ptrval) [00000020] *pgd=00000000 Internal error: Oops: 5 [#1] PREEMPT ARM Modules linked in: CPU: 0 PID: 1 Comm: swapper Not tainted 5.15.0 #1 Hardware name: Generic DT based system PC is at da850_evm_config_emac+0x1c/0x120 LR is at do_one_initcall+0x50/0x1e0
The emac_pdata pointer in soc_info is NULL because davinci_soc_info only gets populated on davinci machines but da850_evm_config_emac() is called on all machines via device_initcall().
Move the rmii_en assignment below the machine check so that it is only dereferenced when running on a supported SoC.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-intel-iotgUpgrade linux-ibm-5.4Upgrade linux-raspi-5.4Upgrade linux-gcp-fipsUpgrade linux-oracle-5.4Upgrade linux-gkeUpgrade linux-gcpUpgrade linux-fipsUpgrade linuxUpgrade linux-gcp-5.4Upgrade linux-azure-fipsUpgrade linux-lowlatencyUpgrade linux-kvmUpgrade linux-azure-5.4Upgrade linux-aws-hweUpgrade linux-hwe-5.4Upgrade linux-aws-fipsUpgrade linux-hwe-5.15Upgrade linux-awsUpgrade linux-realtimeUpgrade linux-hweUpgrade linux-azure-5.15Upgrade linux-gcp-4.15Upgrade linux-oracleUpgrade linux-raspiUpgrade linux-azure-4.15Upgrade linux-intel-iotg-5.15Upgrade linux-iotUpgrade linux-azureUpgrade linux-aws-5.4Upgrade linux-ibmUpgrade linux-bluefieldUpgrade linux-lowlatency-hwe-5.15 | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub