{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.13-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  gpio: mvebu: fix NULL pointer dereference in suspend/resume  mvebu_pwm_suspend() and mvebu_pwm_resume() are called for all GPIO banks during suspend/resume, but not all banks have PWM functionality. GPIO banks without PWM have mvchip-\u003emvpwm set to NULL.  Calling mvebu_pwm_suspend() with mvpwm == NULL causes a NULL pointer dereference when it tries to access mvpwm-\u003eblink_select.    Unable to handle kernel NULL pointer dereference at virtual address 00000020 when write   [00000020] *pgd=00000000   Internal error: Oops: 815 [#1] PREEMPT ARM   Modules linked in:   CPU: 0 UID: 0 PID: 406 Comm: sh Not tainted 6.12.74-rt12-yocto-standard-g4e96f98fb7db-dirty #353   Hardware name: Marvell Armada 370/XP (Device Tree)   PC is at regmap_mmio_read+0x38/0x54   LR is at regmap_mmio_read+0x38/0x54   pc : [\u003cc05fd2ac\u003e]    lr : [\u003cc05fd2ac\u003e]    psr: 200f0013   sp : f0c11d10  ip : 00000000  fp : c100d2f0   r10: c14fb854  r9 : 00000000  r8 : 00000000   r7 : c1799c00  r6 : 00000020  r5 : 00000020  r4 : c179c7c0   r3 : f0a231a0  r2 : 00000020  r1 : 00000020  r0 : 00000000   Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment none   Control: 10c5387d  Table: 135ec059  DAC: 00000051   Call trace:    regmap_mmio_read from _regmap_bus_reg_read+0x78/0xac    _regmap_bus_reg_read from _regmap_read+0x60/0x154    _regmap_read from regmap_read+0x3c/0x60    regmap_read from mvebu_gpio_suspend+0xa4/0x14c    mvebu_gpio_suspend from dpm_run_callback+0x54/0x180    dpm_run_callback from device_suspend+0x124/0x630    device_suspend from dpm_suspend+0x124/0x270    dpm_suspend from dpm_suspend_start+0x64/0x6c    dpm_suspend_start from suspend_devices_and_enter+0x140/0x8e8    suspend_devices_and_enter from pm_suspend+0x2fc/0x308    pm_suspend from state_store+0x6c/0xc8    state_store from kernfs_fop_write_iter+0x10c/0x1f8    kernfs_fop_write_iter from vfs_write+0x270/0x468    vfs_write from ksys_write+0x70/0xf0    ksys_write from ret_fast_syscall+0x0/0x54  Add a NULL check for mvchip-\u003emvpwm before calling the PWM suspend/resume functions.",
  "id": "DEBIAN-CVE-2026-53237",
  "modified": "2026-09-14T16:47:43.700384088Z",
  "published": "2026-06-25T09:16:41.597Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-53237"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-53237"
  ]
}