In the Linux kernel, the following vulnerability has been resolved:
pwm: lpc32xx: Remove handling of PWM channels
Because LPC32xx PWM controllers have only a single output which is registered as the only PWM device/channel per controller, it is known in advance that pwm->hwpwm value is always 0. On basis of this fact simplify the code by removing operations with pwm->hwpwm, there is no controls which require channel number as input.
Even though I wasn't aware at the time when I forward ported that patch, this fixes a null pointer dereference as lpc32xx->chip.pwms is NULL before devm_pwmchip_add() is called.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 3, 2025 | Oct 3, 2025 |
| Ubuntu | — | Upgrade linux-nvidia-tegraUpgrade linux-nvidia-tegra-igxUpgrade linux-gkeopUpgrade linux-gcpUpgrade linux-oracle-5.15Upgrade linux-riscv-5.15Upgrade linux-nvidia-tegra-5.15Upgrade linux-hwe-5.4Upgrade linux-azure-5.15Upgrade linux-azure-fipsUpgrade linux-ibm-5.15Upgrade linux-aws-fipsUpgrade linux-gcp-5.4Upgrade linux-ibm-5.4Upgrade linux-ibmUpgrade linuxUpgrade linux-intel-iot-realtimeUpgrade linux-gcp-fipsUpgrade linux-hwe-5.15Upgrade linux-xilinx-zynqmpUpgrade linux-intel-iotg-5.15Upgrade linux-oracleUpgrade linux-kvmUpgrade linux-gkeUpgrade linux-azure-5.4Upgrade linux-raspi-5.4Upgrade linux-bluefieldUpgrade linux-fipsUpgrade linux-awsUpgrade linux-iotUpgrade linux-raspiUpgrade linux-lowlatency-hwe-5.15Upgrade linux-gcp-5.15Upgrade linux-intel-iotgUpgrade linux-realtimeUpgrade linux-oracle-5.4Upgrade linux-lowlatencyUpgrade linux-aws-5.4Upgrade linux-nvidiaUpgrade linux-aws-5.15Upgrade linux-azure | Oct 10, 2025 | Oct 1, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Oct 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub