cbcvebase.
CVE-2025-21841
published 2025-03-07

CVE-2025-21841: In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting amd_pstate_update_limits() takes a…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting amd_pstate_update_limits() takes a cpufreq_policy reference but doesn't decrement the refcount in one of the exit paths, fix that.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.16-1 (forky)linux 6.12.16-1 (forky)
linuxlinux
linuxlinux>= 45722e777fd99ea863fe653c1838d39f678506e2 < 56e6976793c0fcf1638aa534242408ab4e4ca70556e6976793c0fcf1638aa534242408ab4e4ca705
linuxlinux>= 45722e777fd99ea863fe653c1838d39f678506e2 < 28e4c515cf644c621800bd97841757fd49891ba428e4c515cf644c621800bd97841757fd49891ba4
linuxlinux>= 45722e777fd99ea863fe653c1838d39f678506e2 < 3ace20038e19f23fe73259513f1f08d4bf1a3c833ace20038e19f23fe73259513f1f08d4bf1a3c83
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 6.12 < 6.12.166.12.16
linuxlinux_kernel>= 6.13 < 6.13.46.13.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.