In the Linux kernel, the following vulnerability has been resolved:
cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()
cpufreq_cpu_get_raw() can return NULL when the target CPU is not present
in the policy->cpus mask. scpi_cpufreq_get_rate() does not check for
this case, which results in a NULL pointer dereference.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
12 Nov 2025, 21:45
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Debian debian Linux
Linux Debian Linux linux Kernel |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| References | () https://git.kernel.org/stable/c/124bddf123311cd1f18bffd63a5d974468d59c67 - Patch | |
| References | () https://git.kernel.org/stable/c/19e0eaa62e8831f2bc0285fef3bf8faaa7f3e09b - Patch | |
| References | () https://git.kernel.org/stable/c/28fbd7b13b4d3074b16db913aedc9d8d37ab41e7 - Patch | |
| References | () https://git.kernel.org/stable/c/73b24dc731731edf762f9454552cb3a5b7224949 - Patch | |
| References | () https://git.kernel.org/stable/c/8fbaa76690f67a7cbad315f89d607b46e3e06ede - Patch | |
| References | () https://git.kernel.org/stable/c/ad4796f2da495b2cbbd0fccccbcbf63f2aeee613 - Patch | |
| References | () https://git.kernel.org/stable/c/da8ee91e532486055ecf88478d38c2f3dc234182 - Patch | |
| References | () https://git.kernel.org/stable/c/fdf035d9c5436536ffcfea0ac6adeb5dda3c3a23 - Patch | |
| References | () https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html - Mailing List, Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html - Mailing List, Third Party Advisory | |
| CWE | CWE-476 | |
| CPE | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:* |
03 Nov 2025, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 May 2025, 14:39
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
08 May 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-08 07:15
Updated : 2025-11-12 21:45
NVD link : CVE-2025-37829
Mitre link : CVE-2025-37829
CVE.ORG link : CVE-2025-37829
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
CWE-476
NULL Pointer Dereference
