CVE-2025-23137

MEDIUM

Linux Kernel 6.11-6.14.2 - NULL Pointer Dereference in amd_pstate_update

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update Check if policy is NULL before dereferencing it in amd_pstate_update.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (11)
linux/Kernel 6.11.0 - 6.12.35linux
linux/Kernel 6.13.0 - 6.14.2linux
Linux/Linux < 6.11
Linux/Linux 6.11
Linux/Linux 6.12.35 - 6.12.*
Linux/Linux 6.14.2 - 6.14.*
Linux/Linux 6.15
Linux/Linux e8f555daacd3377bf691fdda2490c0b164e00085 - 426db24d4db2e4f0d6720aeb7795eafcb9e82640
Linux/Linux e8f555daacd3377bf691fdda2490c0b164e00085 - 82b6dfff0d6000b14b271f74e43d672d81fb390e
Linux/Linux e8f555daacd3377bf691fdda2490c0b164e00085 - b99c1c63d88c75a4dc5487c3696cda38697b8d35
... and 1 more
Published Apr 16, 2025
Tracked Since Feb 18, 2026