cbcvebase.
CVE-2025-38297
published 2025-07-10

CVE-2025-38297: In the Linux kernel, the following vulnerability has been resolved: PM: EM: Fix potential division-by-zero error in em_compute_costs() When the device is of a…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: PM: EM: Fix potential division-by-zero error in em_compute_costs() When the device is of a non-CPU type, table[i].performance won't be initialized in the previous em_init_performance(), resulting in division by zero when calculating costs in em_compute_costs(). Since the 'cost' algorithm is only used for EAS energy efficiency calculations and is currently not utilized by other device drivers, we should add the _is_cpu_device(dev) check to prevent this division-by-zero issue.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
linuxlinux
linuxlinux>= 1b600da510735a0f92c8b4140a7e2cb037a6a6c3 < 81d72f9241d884ec29524431f74f8009310cfa0c81d72f9241d884ec29524431f74f8009310cfa0c
linuxlinux>= 1b600da510735a0f92c8b4140a7e2cb037a6a6c3 < 14cbdd64f3870cf0a2d94b87919b9056448c59a014cbdd64f3870cf0a2d94b87919b9056448c59a0
linuxlinux>= 1b600da510735a0f92c8b4140a7e2cb037a6a6c3 < 179c0c7044a378198adb36f2a12410ab68cc730a179c0c7044a378198adb36f2a12410ab68cc730a
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 6.13 < 6.15.36.15.3
linuxlinux_kernel>= 6.9 < 6.12.346.12.34
msrccbl2_golang_1.17.8-1_on_cbl_mariner_2.0
msrccm1_golang_1.16.9-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_msrc9.8CRITICAL
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.