cbcvebase.
CVE-2025-40194
published 2025-11-12

CVE-2025-40194: In the Linux kernel, the following vulnerability has been resolved: cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() The…

PriorityP421high7.8
EPSS
0.20%
9.7th percentile
In the Linux kernel, the following vulnerability has been resolved: cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() The cpufreq_cpu_put() call in update_qos_request() takes place too early because the latter subsequently calls freq_qos_update_request() that indirectly accesses the policy object in question through the QoS request object passed to it. Fortunately, update_qos_request() is called under intel_pstate_driver_lock, so this issue does not matter for changing the intel_pstate operation mode, but it theoretically can cause a crash to occur on CPU device hot removal (which currently can only happen in virt, but it is formally supported nevertheless). Address this issue by modifying update_qos_request() to drop the reference to the policy later.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= da5c504c7aae96db68c4b38e2564a88e91842d89 < 15ac9579ebdaf22a37d7f60b3a8efc1029732ef915ac9579ebdaf22a37d7f60b3a8efc1029732ef9
linuxlinux>= da5c504c7aae96db68c4b38e2564a88e91842d89 < bc26564bcc659beb6d977cd6eb394041ec2f2851bc26564bcc659beb6d977cd6eb394041ec2f2851
linuxlinux>= da5c504c7aae96db68c4b38e2564a88e91842d89 < ad4e8f9bdbef11a19b7cb93e7f313bf59bdcc3b4ad4e8f9bdbef11a19b7cb93e7f313bf59bdcc3b4
linuxlinux>= da5c504c7aae96db68c4b38e2564a88e91842d89 < 0a58d3e77b22b087a57831c87cafd360e144a5bd0a58d3e77b22b087a57831c87cafd360e144a5bd
linuxlinux>= da5c504c7aae96db68c4b38e2564a88e91842d89 < 69a18ff6c60e8e113420f15355fad862cb45d38e69a18ff6c60e8e113420f15355fad862cb45d38e
linuxlinux>= da5c504c7aae96db68c4b38e2564a88e91842d89 < ba63d4e9857a72a89e71a4eff9f2cc8c283e94c3ba63d4e9857a72a89e71a4eff9f2cc8c283e94c3
linuxlinux>= da5c504c7aae96db68c4b38e2564a88e91842d89 < 57e4a6aadf12578b96a038373cffd54b3a58b09257e4a6aadf12578b96a038373cffd54b3a58b092
linuxlinux>= da5c504c7aae96db68c4b38e2564a88e91842d89 < 69e5d50fcf4093fb3f9f41c4f931f12c2ca8c46769e5d50fcf4093fb3f9f41c4f931f12c2ca8c467
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1576.1.157
linuxlinux_kernel>= 5.4.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.46.17.4
linuxlinux_kernel>= 6.2.0 < 6.6.1136.6.113
linuxlinux_kernel>= 6.7.0 < 6.12.546.12.54

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.8MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.