In the Linux kernel, the following vulnerability has been resolved:
gpio: Restrict usage of GPIO chip irq members before initialization
GPIO chip irq members are exposed before they could be completely initialized and this leads to race conditions.
One such issue was observed for the gc->irq.domain variable which was accessed through the I2C interface in gpiochip_to_irq() before it could be initialized by gpiochip_add_irqchip(). This resulted in Kernel NULL pointer dereference.
Following are the logs for reference :-
kernel: Call Trace: kernel: gpiod_to_irq+0x53/0x70 kernel: acpi_dev_gpio_irq_get_by+0x113/0x1f0 kernel: i2c_acpi_get_irq+0xc0/0xd0 kernel: i2c_device_probe+0x28a/0x2a0 kernel: really_probe+0xf2/0x460 kernel: RIP: 0010:gpiochip_to_irq+0x47/0xc0
To avoid such scenarios, restrict usage of GPIO chip irq members before they are completely initialized.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-headersUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-develUpgrade kernelUpgrade kernel-debuginfoUpgrade perf-debuginfoUpgrade perfUpgrade kernel-develUpgrade kernel-tools-debuginfoUpgrade kernel-toolsUpgrade bpftool-debuginfoUpgrade kernel-livepatch-5.10.112-108.499Upgrade python-perfUpgrade python-perf-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade bpftool | May 22, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade kernel-toolsUpgrade bpftoolUpgrade kernel-tools-libsUpgrade python3-perfUpgrade kernelUpgrade kernel-abi-stablelists | Aug 13, 2025 | Jun 30, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-abi-stablelistsUpgrade kernel-toolsUpgrade kernelUpgrade python3-perfUpgrade bpftoolUpgrade kernel-tools-libs | Jul 1, 2025 | Feb 26, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-image-kvm-5.4Upgrade linux-image-5.4.0-227-genericUpgrade linux-image-lowlatency-5.4Upgrade linux-image-aws-5.4Upgrade linux-image-genericUpgrade linux-image-generic-lpaeUpgrade linux-image-xilinx-zynqmp-5.4Upgrade linux-image-lowlatency-hwe-18.04Upgrade linux-image-aws-fips-5.4Upgrade linux-image-snapdragon-hwe-18.04Upgrade linux-image-oemUpgrade linux-image-azure-5.4Upgrade linux-image-fipsUpgrade linux-image-aws-fipsUpgrade linux-image-virtual-5.4Upgrade linux-image-5.4.0-227-lowlatencyUpgrade linux-image-5.4.0-1160-azureUpgrade linux-image-lowlatencyUpgrade linux-image-5.4.0-227-generic-lpaeUpgrade linux-image-5.4.0-1155-aws-fipsUpgrade linux-image-5.4.0-1159-gcpUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-5.4.0-1143-kvmUpgrade linux-image-generic-lpae-5.4Upgrade linux-image-virtualUpgrade linux-image-oracle-lts-20.04Upgrade linux-image-oem-osp1Upgrade linux-image-raspi-hwe-18.04Upgrade linux-image-azure-lts-20.04Upgrade linux-image-azureUpgrade linux-image-generic-5.4Upgrade linux-image-raspi2Upgrade linux-image-raspiUpgrade linux-image-5.4.0-1154-oracleUpgrade linux-image-generic-hwe-18.04Upgrade linux-image-ibm-5.4Upgrade linux-image-5.4.0-1060-iotUpgrade linux-image-aws-lts-20.04Upgrade linux-image-fips-5.4Upgrade linux-image-5.4.0-1139-raspiUpgrade linux-image-ibm-lts-20.04Upgrade linux-image-5.4.0-1130-fipsUpgrade linux-image-5.4.0-1161-azureUpgrade linux-image-5.4.0-1159-gcp-fipsUpgrade linux-image-oracleUpgrade linux-image-5.4.0-1102-ibmUpgrade linux-image-gcp-fipsUpgrade linux-image-azure-fipsUpgrade linux-image-gcpUpgrade linux-image-gcp-fips-5.4Upgrade linux-image-virtual-hwe-18.04Upgrade linux-image-gcp-lts-20.04Upgrade linux-image-azure-fips-5.4Upgrade linux-image-kvmUpgrade linux-image-5.4.0-1160-azure-fipsUpgrade linux-image-raspi-5.4Upgrade linux-image-5.4.0-1156-awsUpgrade linux-image-5.4.0-1074-xilinx-zynqmpUpgrade linux-image-snapdragon-5.4Upgrade linux-image-oracle-5.4Upgrade linux-image-awsUpgrade linux-image-ibmUpgrade linux-image-gcp-5.4 | Mar 19, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub