cbcvebase.
CVE-2025-23136
published 2025-04-16

CVE-2025-23136: In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companion fwnode, so…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companion fwnode, so adev might be NULL. This is similar to the commit cd2fd6eab480 ("platform/x86: int3472: Check for adev == NULL"). Add a check for adev not being set and return -ENODEV in that case to avoid a possible NULL pointer deref in int3402_thermal_probe(). Note, under the same directory, int3400_thermal_probe() has such a check. [ rjw: Subject edit, added Fixes: ]

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < d0d21c8e44216fa9afdb3809edf213f3c0a8c060d0d21c8e44216fa9afdb3809edf213f3c0a8c060
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < bc7b5f782d28942dbdfda70df30ce132694a06debc7b5f782d28942dbdfda70df30ce132694a06de
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < 3155d5261b518776d1b807d9d922669991bbee563155d5261b518776d1b807d9d922669991bbee56
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < 6a810c462f099353e908c70619638884cb82229c6a810c462f099353e908c70619638884cb82229c
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < ac2eb7378319e3836cdf3a2c15a0bdf04c50e81dac2eb7378319e3836cdf3a2c15a0bdf04c50e81d
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < 953d28a4f459fcbde2d08f51aeca19d6b0f179f3953d28a4f459fcbde2d08f51aeca19d6b0f179f3
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < 0c49f12c77b77a706fd41370c11910635e4918450c49f12c77b77a706fd41370c11910635e491845
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < 8e8f1ddf4186731649df8bc9646017369eb191868e8f1ddf4186731649df8bc9646017369eb19186
linuxlinux>= 77e337c6e23e3b9d22e09ffec202a80f755a54c2 < 2542a3f70e563a9e70e7ded314286535a3321bdb2542a3f70e563a9e70e7ded314286535a3321bdb
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 3.18 < 5.4.2925.4.292
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1346.1.134
linuxlinux_kernel>= 5.5 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.116.13.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.