cbcvebase.
CVE-2025-40346
published 2025-12-16

CVE-2025-40346: In the Linux kernel, the following vulnerability has been resolved: arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() Fix incorrect use…

PriorityP420high7.8
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() Fix incorrect use of PTR_ERR_OR_ZERO() in topology_parse_cpu_capacity() which causes the code to proceed with NULL clock pointers. The current logic uses !PTR_ERR_OR_ZERO(cpu_clk) which evaluates to true for both valid pointers and NULL, leading to potential NULL pointer dereference in clk_get_rate(). Per include/linux/err.h documentation, PTR_ERR_OR_ZERO(ptr) returns: "The error code within @ptr if it is an error pointer; 0 otherwise." This means PTR_ERR_OR_ZERO() returns 0 for both valid pointers AND NULL pointers. Therefore !PTR_ERR_OR_ZERO(cpu_clk) evaluates to true (proceed) when cpu_clk is either valid or NULL, causing clk_get_rate(NULL) to be called when of_clk_get() returns NULL. Replace with !IS_ERR_OR_NULL(cpu_clk) which only proceeds for valid pointers, preventing potential NULL pointer dereference in clk_get_rate().

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= b8fe128dad8f97cc9af7c55a264d1fc5ab677195 < 64da320252e43456cc9ec3055ff567f168467b3764da320252e43456cc9ec3055ff567f168467b37
linuxlinux>= b8fe128dad8f97cc9af7c55a264d1fc5ab677195 < 02fbea0864fd4a863671f5d418129258d7159f6802fbea0864fd4a863671f5d418129258d7159f68
linuxlinux>= b8fe128dad8f97cc9af7c55a264d1fc5ab677195 < a77f8434954cb1e9c42c3854e40855fdcf5ab235a77f8434954cb1e9c42c3854e40855fdcf5ab235
linuxlinux>= b8fe128dad8f97cc9af7c55a264d1fc5ab677195 < 3373f263bb647fcc3b5237cfaef757633b9ee25e3373f263bb647fcc3b5237cfaef757633b9ee25e
linuxlinux>= b8fe128dad8f97cc9af7c55a264d1fc5ab677195 < 45379303124487db3a81219af7565d41f498167f45379303124487db3a81219af7565d41f498167f
linuxlinux>= b8fe128dad8f97cc9af7c55a264d1fc5ab677195 < 3a01b2614e84361aa222f67bc628593987e5cdb23a01b2614e84361aa222f67bc628593987e5cdb2
linuxlinux>= b8fe128dad8f97cc9af7c55a264d1fc5ab677195 < 2eead19334516c8e9927c11b448fbe512b1f18a12eead19334516c8e9927c11b448fbe512b1f18a1
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.11.0 < 5.15.1965.15.196
linuxlinux_kernel>= 5.16.0 < 6.1.1586.1.158
linuxlinux_kernel>= 5.7.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.66.17.6
linuxlinux_kernel>= 6.2.0 < 6.6.1156.6.115
linuxlinux_kernel>= 6.7.0 < 6.12.566.12.56
ubuntulinux-aws
ubuntulinux-azure-5.15
ubuntulinux-intel-iotg-5.15

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.