In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup The kthread_run() function returns error pointers so the max3421_hcd->spi_thread pointer can be either error pointers or NULL. Check for both before dereferencing it.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025111251-CVE-2025-40116-3942@gregkh/T