cbcvebase.
CVE-2025-37831
published 2025-05-08

CVE-2025-37831: In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate() cpufreq_cpu_get_raw() can return NULL when the target CPU is not present in the policy->cpus mask. apple_soc_cpufreq_get_rate() does not check for this case, which results in a NULL pointer dereference.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.27-1 (forky)linux 6.12.27-1 (forky)
linuxlinux
linuxlinux>= 6286bbb40576ffadfde206c332b61345c19af57f < 1053dcf8a504d4933bb3f73df22bc363298d194b1053dcf8a504d4933bb3f73df22bc363298d194b
linuxlinux>= 6286bbb40576ffadfde206c332b61345c19af57f < fbdba5f37413dbc09d82ad7235e5b7a2fb8e0f75fbdba5f37413dbc09d82ad7235e5b7a2fb8e0f75
linuxlinux>= 6286bbb40576ffadfde206c332b61345c19af57f < 01e86ea22610d98ae6141e428019a6916e79f72501e86ea22610d98ae6141e428019a6916e79f725
linuxlinux>= 6286bbb40576ffadfde206c332b61345c19af57f < 9992649f6786921873a9b89dafa5e04d8c5fef2b9992649f6786921873a9b89dafa5e04d8c5fef2b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.14.56.14.5
linuxlinux_kernel>= 6.2 < 6.6.896.6.89
linuxlinux_kernel>= 6.7 < 6.12.266.12.26
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime
ubuntulinux-realtime

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.