
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-37972 is a vulnerability discovered in the Linux kernel affecting the MTK PMIC keys driver. The vulnerability was disclosed on May 20, 2025, and involves a potential null pointer dereference in the mtkpmickeys_probe function (NVD).
The vulnerability occurs in the mtkpmickeys_probe function where the regs parameter is only set if the button is parsed in the device tree. On hardware where the button is left floating, the node will likely be removed to disable that input, leading to a potential null pointer dereference. The issue arises because the code attempts to dereference a null pointer in such cases (NVD).
The vulnerability could lead to a system crash or denial of service condition when the affected code path is triggered, particularly on systems using the MTK PMIC keys driver with specific hardware configurations (NVD).
The vulnerability has been fixed in Linux kernel version 6.1.140-1 for the Debian stable distribution (bookworm). The fix involves using the regs struct instead of the regs parameter, as it is defined for all supported platforms (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."