cbcvebase.
CVE-2025-38610
published 2025-08-19

CVE-2025-38610: In the Linux kernel, the following vulnerability has been resolved: powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw() The get_pd_power_uw()…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw() The get_pd_power_uw() function can crash with a NULL pointer dereference when em_cpu_get() returns NULL. This occurs when a CPU becomes impossible during runtime, causing get_cpu_device() to return NULL, which propagates through em_cpu_get() and leads to a crash when em_span_cpus() dereferences the NULL pointer. Add a NULL check after em_cpu_get() and return 0 if unavailable, matching the existing fallback behavior in __dtpm_cpu_setup(). [ rjw: Drop an excess empty code line ]

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.148-1 (bookworm)linux 6.1.148-1 (bookworm)
debianlinux-6.1< linux 6.1.148-1 (bookworm)linux 6.1.148-1 (bookworm)
linuxlinux
linuxlinux>= eb82bace893169b319c563b7f813c58a0a5a9f76 < 27914f2b795e2b58e9506f281dcdd98fef09d3c227914f2b795e2b58e9506f281dcdd98fef09d3c2
linuxlinux>= eb82bace893169b319c563b7f813c58a0a5a9f76 < c6ec27091cf5ac05094c1fe3a6ce914cf711a37cc6ec27091cf5ac05094c1fe3a6ce914cf711a37c
linuxlinux>= eb82bace893169b319c563b7f813c58a0a5a9f76 < 8374ac7d69a57d737e701a851ffe980a0d27d3ad8374ac7d69a57d737e701a851ffe980a0d27d3ad
linuxlinux>= eb82bace893169b319c563b7f813c58a0a5a9f76 < 27e0318f0ea69fcfa32228847debc384ade1457827e0318f0ea69fcfa32228847debc384ade14578
linuxlinux>= eb82bace893169b319c563b7f813c58a0a5a9f76 < 2fd001a0075ac01dc64a28a8e21226b3d989a91d2fd001a0075ac01dc64a28a8e21226b3d989a91d
linuxlinux>= eb82bace893169b319c563b7f813c58a0a5a9f76 < 46dc57406887dd02565cb264224194a6776d882b46dc57406887dd02565cb264224194a6776d882b
linuxlinux_kernel>= 0 < 6.1.148-16.1.148-1
linuxlinux_kernel>= 0 < 6.12.43-16.12.43-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.16 < 6.1.1486.1.148
linuxlinux_kernel>= 6.13 < 6.15.106.15.10
linuxlinux_kernel>= 6.16 < 6.16.16.16.1
linuxlinux_kernel>= 6.2 < 6.6.1026.6.102
linuxlinux_kernel>= 6.7 < 6.12.426.12.42
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM