CVE-2025-21918

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-21918
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21918.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21918
Downstream
Related
Published
2025-04-01T15:40:53Z
Modified
2025-10-17T22:48:09.876130Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
usb: typec: ucsi: Fix NULL pointer access
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: ucsi: Fix NULL pointer access

Resources should be released only after all threads that utilize them have been destroyed. This commit ensures that resources are not released prematurely by waiting for the associated workqueue to complete before deallocating them.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b9aa02ca39a49740926c2c450a1505a4a0f8954a
Fixed
7a735a8a46f6ebf898bbefd96659ca5da798bce0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b9aa02ca39a49740926c2c450a1505a4a0f8954a
Fixed
46fba7be161bb89068958138ea64ec33c0b446d4
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b9aa02ca39a49740926c2c450a1505a4a0f8954a
Fixed
079a3e52f3e751bb8f5937195bdf25c5d14fdff0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b9aa02ca39a49740926c2c450a1505a4a0f8954a
Fixed
592a0327d026a122e97e8e8bb7c60cbbe7697344
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b9aa02ca39a49740926c2c450a1505a4a0f8954a
Fixed
b13abcb7ddd8d38de769486db5bd917537b32ab1

Affected versions

v5.*

v5.15
v5.15-rc4
v5.15-rc5
v5.15-rc6
v5.15-rc7
v5.16
v5.16-rc1
v5.16-rc2
v5.16-rc3
v5.16-rc4
v5.16-rc5
v5.16-rc6
v5.16-rc7
v5.16-rc8
v5.17
v5.17-rc1
v5.17-rc2
v5.17-rc3
v5.17-rc4
v5.17-rc5
v5.17-rc6
v5.17-rc7
v5.17-rc8
v5.18
v5.18-rc1
v5.18-rc2
v5.18-rc3
v5.18-rc4
v5.18-rc5
v5.18-rc6
v5.18-rc7
v5.19
v5.19-rc1
v5.19-rc2
v5.19-rc3
v5.19-rc4
v5.19-rc5
v5.19-rc6
v5.19-rc7
v5.19-rc8

v6.*

v6.0
v6.0-rc1
v6.0-rc2
v6.0-rc3
v6.0-rc4
v6.0-rc5
v6.0-rc6
v6.0-rc7
v6.1
v6.1-rc1
v6.1-rc2
v6.1-rc3
v6.1-rc4
v6.1-rc5
v6.1-rc6
v6.1-rc7
v6.1-rc8
v6.1.1
v6.1.10
v6.1.100
v6.1.101
v6.1.102
v6.1.103
v6.1.104
v6.1.105
v6.1.106
v6.1.107
v6.1.108
v6.1.109
v6.1.11
v6.1.110
v6.1.111
v6.1.112
v6.1.113
v6.1.114
v6.1.115
v6.1.116
v6.1.117
v6.1.118
v6.1.119
v6.1.12
v6.1.120
v6.1.121
v6.1.122
v6.1.123
v6.1.124
v6.1.125
v6.1.126
v6.1.127
v6.1.128
v6.1.129
v6.1.13
v6.1.130
v6.1.131
v6.1.132
v6.1.14
v6.1.15
v6.1.16
v6.1.17
v6.1.18
v6.1.19
v6.1.2
v6.1.20
v6.1.21
v6.1.22
v6.1.23
v6.1.24
v6.1.25
v6.1.26
v6.1.27
v6.1.28
v6.1.29
v6.1.3
v6.1.30
v6.1.31
v6.1.32
v6.1.33
v6.1.34
v6.1.35
v6.1.36
v6.1.37
v6.1.38
v6.1.39
v6.1.4
v6.1.40
v6.1.41
v6.1.42
v6.1.43
v6.1.44
v6.1.45
v6.1.46
v6.1.47
v6.1.48
v6.1.49
v6.1.5
v6.1.50
v6.1.51
v6.1.52
v6.1.53
v6.1.54
v6.1.55
v6.1.56
v6.1.57
v6.1.58
v6.1.59
v6.1.6
v6.1.60
v6.1.61
v6.1.62
v6.1.63
v6.1.64
v6.1.65
v6.1.66
v6.1.67
v6.1.68
v6.1.69
v6.1.7
v6.1.70
v6.1.71
v6.1.72
v6.1.73
v6.1.74
v6.1.75
v6.1.76
v6.1.77
v6.1.78
v6.1.79
v6.1.8
v6.1.80
v6.1.81
v6.1.82
v6.1.83
v6.1.84
v6.1.85
v6.1.86
v6.1.87
v6.1.88
v6.1.89
v6.1.9
v6.1.90
v6.1.91
v6.1.92
v6.1.93
v6.1.94
v6.1.95
v6.1.96
v6.1.97
v6.1.98
v6.1.99
v6.10
v6.10-rc1
v6.10-rc2
v6.10-rc3
v6.10-rc4
v6.10-rc5
v6.10-rc6
v6.10-rc7
v6.11
v6.11-rc1
v6.11-rc2
v6.11-rc3
v6.11-rc4
v6.11-rc5
v6.11-rc6
v6.11-rc7
v6.12
v6.12-rc1
v6.12-rc2
v6.12-rc3
v6.12-rc4
v6.12-rc5
v6.12-rc6
v6.12-rc7
v6.12.1
v6.12.10
v6.12.11
v6.12.12
v6.12.13
v6.12.14
v6.12.15
v6.12.16
v6.12.17
v6.12.18
v6.12.2
v6.12.3
v6.12.4
v6.12.5
v6.12.6
v6.12.7
v6.12.8
v6.12.9
v6.13
v6.13-rc1
v6.13-rc2
v6.13-rc3
v6.13-rc4
v6.13-rc5
v6.13-rc6
v6.13-rc7
v6.13.1
v6.13.2
v6.13.3
v6.13.4
v6.13.5
v6.13.6
v6.14-rc1
v6.14-rc2
v6.14-rc3
v6.2
v6.2-rc1
v6.2-rc2
v6.2-rc3
v6.2-rc4
v6.2-rc5
v6.2-rc6
v6.2-rc7
v6.2-rc8
v6.3
v6.3-rc1
v6.3-rc2
v6.3-rc3
v6.3-rc4
v6.3-rc5
v6.3-rc6
v6.3-rc7
v6.4
v6.4-rc1
v6.4-rc2
v6.4-rc3
v6.4-rc4
v6.4-rc5
v6.4-rc6
v6.4-rc7
v6.5
v6.5-rc1
v6.5-rc2
v6.5-rc3
v6.5-rc4
v6.5-rc5
v6.5-rc6
v6.5-rc7
v6.6
v6.6-rc1
v6.6-rc2
v6.6-rc3
v6.6-rc4
v6.6-rc5
v6.6-rc6
v6.6-rc7
v6.6.1
v6.6.10
v6.6.11
v6.6.12
v6.6.13
v6.6.14
v6.6.15
v6.6.16
v6.6.17
v6.6.18
v6.6.19
v6.6.2
v6.6.20
v6.6.21
v6.6.22
v6.6.23
v6.6.24
v6.6.25
v6.6.26
v6.6.27
v6.6.28
v6.6.29
v6.6.3
v6.6.30
v6.6.31
v6.6.32
v6.6.33
v6.6.34
v6.6.35
v6.6.36
v6.6.37
v6.6.38
v6.6.39
v6.6.4
v6.6.40
v6.6.41
v6.6.42
v6.6.43
v6.6.44
v6.6.45
v6.6.46
v6.6.47
v6.6.48
v6.6.49
v6.6.5
v6.6.50
v6.6.51
v6.6.52
v6.6.53
v6.6.54
v6.6.55
v6.6.56
v6.6.57
v6.6.58
v6.6.59
v6.6.6
v6.6.60
v6.6.61
v6.6.62
v6.6.63
v6.6.64
v6.6.65
v6.6.66
v6.6.67
v6.6.68
v6.6.69
v6.6.7
v6.6.70
v6.6.71
v6.6.72
v6.6.73
v6.6.74
v6.6.75
v6.6.76
v6.6.77
v6.6.78
v6.6.79
v6.6.8
v6.6.80
v6.6.81
v6.6.82
v6.6.9
v6.7
v6.7-rc1
v6.7-rc2
v6.7-rc3
v6.7-rc4
v6.7-rc5
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.8
v6.8-rc1
v6.8-rc2
v6.8-rc3
v6.8-rc4
v6.8-rc5
v6.8-rc6
v6.8-rc7
v6.9
v6.9-rc1
v6.9-rc2
v6.9-rc3
v6.9-rc4
v6.9-rc5
v6.9-rc6
v6.9-rc7

Database specific

vanir_signatures

[
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@46fba7be161bb89068958138ea64ec33c0b446d4",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_init"
        },
        "digest": {
            "function_hash": "200352868041582235020623647015866293906",
            "length": 1917.0
        },
        "id": "CVE-2025-21918-053cd2fc",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b13abcb7ddd8d38de769486db5bd917537b32ab1",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_unregister"
        },
        "digest": {
            "function_hash": "106983552702440418413237965727013980306",
            "length": 1270.0
        },
        "id": "CVE-2025-21918-05da4e52",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@592a0327d026a122e97e8e8bb7c60cbbe7697344",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_unregister"
        },
        "digest": {
            "function_hash": "106983552702440418413237965727013980306",
            "length": 1270.0
        },
        "id": "CVE-2025-21918-0ea005a3",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@592a0327d026a122e97e8e8bb7c60cbbe7697344",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_init"
        },
        "digest": {
            "function_hash": "235813378699851016461133891602819231836",
            "length": 1905.0
        },
        "id": "CVE-2025-21918-1d33dd59",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@46fba7be161bb89068958138ea64ec33c0b446d4",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_unregister"
        },
        "digest": {
            "function_hash": "212932672981723439746756804491162327447",
            "length": 1302.0
        },
        "id": "CVE-2025-21918-3e148d32",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7a735a8a46f6ebf898bbefd96659ca5da798bce0",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_init"
        },
        "digest": {
            "function_hash": "323463394843155466765532806438801729207",
            "length": 1733.0
        },
        "id": "CVE-2025-21918-7677f224",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7a735a8a46f6ebf898bbefd96659ca5da798bce0",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_unregister"
        },
        "digest": {
            "function_hash": "251271775317499029778327457863509764527",
            "length": 986.0
        },
        "id": "CVE-2025-21918-86680e5f",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@592a0327d026a122e97e8e8bb7c60cbbe7697344",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c"
        },
        "digest": {
            "line_hashes": [
                "81787596694488019697335171070277928174",
                "327550212132597115104636591042973773092",
                "161851520669941249387558026955424395084",
                "83131789802856630775713298130869097671",
                "20071328129433131307879550800839372160",
                "152165656035133958735857901626908529345",
                "284454322279873775434031576028399886096",
                "226552152406147829481433901461110247060",
                "13858440103804205791053262403132750830",
                "102773066058946725140074325066017876594",
                "154576385147187285077395431660814944789",
                "310690178935682754757754777383216291241",
                "139635054539830590845697452465775016296",
                "91904537278911182031606042955855258792",
                "52539443522090958190651722526324016937",
                "196911016005024834612570378861530688291",
                "147618802302485825042820570055863359593",
                "247252785445898022657680858043720469519",
                "32873961597371760640032277375972265579"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-21918-889437d6",
        "signature_type": "Line",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7a735a8a46f6ebf898bbefd96659ca5da798bce0",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c"
        },
        "digest": {
            "line_hashes": [
                "81787596694488019697335171070277928174",
                "327550212132597115104636591042973773092",
                "161851520669941249387558026955424395084",
                "83131789802856630775713298130869097671",
                "20071328129433131307879550800839372160",
                "152165656035133958735857901626908529345",
                "65279742427862364437896543369710939077",
                "307472042136500998759032533219803740191",
                "176258701606925971105853745778169090667",
                "102773066058946725140074325066017876594",
                "154576385147187285077395431660814944789",
                "310690178935682754757754777383216291241",
                "139635054539830590845697452465775016296",
                "91904537278911182031606042955855258792",
                "52539443522090958190651722526324016937",
                "196911016005024834612570378861530688291",
                "5776891657981229021771155901841966292",
                "171990744577680693407789965721959828481",
                "267772971793541228094088761242962546423",
                "30925055317837417635545115348139569514"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-21918-ad4db773",
        "signature_type": "Line",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b13abcb7ddd8d38de769486db5bd917537b32ab1",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c"
        },
        "digest": {
            "line_hashes": [
                "81787596694488019697335171070277928174",
                "327550212132597115104636591042973773092",
                "161851520669941249387558026955424395084",
                "83131789802856630775713298130869097671",
                "20071328129433131307879550800839372160",
                "152165656035133958735857901626908529345",
                "284454322279873775434031576028399886096",
                "226552152406147829481433901461110247060",
                "13858440103804205791053262403132750830",
                "102773066058946725140074325066017876594",
                "154576385147187285077395431660814944789",
                "310690178935682754757754777383216291241",
                "139635054539830590845697452465775016296",
                "91904537278911182031606042955855258792",
                "52539443522090958190651722526324016937",
                "196911016005024834612570378861530688291",
                "147618802302485825042820570055863359593",
                "247252785445898022657680858043720469519",
                "32873961597371760640032277375972265579"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-21918-cb6ec63d",
        "signature_type": "Line",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@079a3e52f3e751bb8f5937195bdf25c5d14fdff0",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_unregister"
        },
        "digest": {
            "function_hash": "106983552702440418413237965727013980306",
            "length": 1270.0
        },
        "id": "CVE-2025-21918-d594778d",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@079a3e52f3e751bb8f5937195bdf25c5d14fdff0",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c"
        },
        "digest": {
            "line_hashes": [
                "81787596694488019697335171070277928174",
                "327550212132597115104636591042973773092",
                "161851520669941249387558026955424395084",
                "83131789802856630775713298130869097671",
                "20071328129433131307879550800839372160",
                "152165656035133958735857901626908529345",
                "284454322279873775434031576028399886096",
                "226552152406147829481433901461110247060",
                "13858440103804205791053262403132750830",
                "102773066058946725140074325066017876594",
                "154576385147187285077395431660814944789",
                "310690178935682754757754777383216291241",
                "139635054539830590845697452465775016296",
                "91904537278911182031606042955855258792",
                "52539443522090958190651722526324016937",
                "196911016005024834612570378861530688291",
                "147618802302485825042820570055863359593",
                "247252785445898022657680858043720469519",
                "32873961597371760640032277375972265579"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-21918-d9d68f06",
        "signature_type": "Line",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@079a3e52f3e751bb8f5937195bdf25c5d14fdff0",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_init"
        },
        "digest": {
            "function_hash": "325529737810862212511180518499785778462",
            "length": 1891.0
        },
        "id": "CVE-2025-21918-e1e7da2c",
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@46fba7be161bb89068958138ea64ec33c0b446d4",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c"
        },
        "digest": {
            "line_hashes": [
                "81787596694488019697335171070277928174",
                "327550212132597115104636591042973773092",
                "161851520669941249387558026955424395084",
                "83131789802856630775713298130869097671",
                "20071328129433131307879550800839372160",
                "152165656035133958735857901626908529345",
                "284454322279873775434031576028399886096",
                "226552152406147829481433901461110247060",
                "13858440103804205791053262403132750830",
                "102773066058946725140074325066017876594",
                "154576385147187285077395431660814944789",
                "310690178935682754757754777383216291241",
                "139635054539830590845697452465775016296",
                "91904537278911182031606042955855258792",
                "52539443522090958190651722526324016937",
                "196911016005024834612570378861530688291",
                "147618802302485825042820570055863359593",
                "247252785445898022657680858043720469519",
                "32873961597371760640032277375972265579"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-21918-e4aa7e38",
        "signature_type": "Line",
        "signature_version": "v1"
    },
    {
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b13abcb7ddd8d38de769486db5bd917537b32ab1",
        "deprecated": false,
        "target": {
            "file": "drivers/usb/typec/ucsi/ucsi.c",
            "function": "ucsi_init"
        },
        "digest": {
            "function_hash": "235813378699851016461133891602819231836",
            "length": 1905.0
        },
        "id": "CVE-2025-21918-fbe749ae",
        "signature_type": "Function",
        "signature_version": "v1"
    }
]

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.133
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.83
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.19
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.7