cbcvebase.
CVE-2025-68177
published 2025-12-16

CVE-2025-68177: In the Linux kernel, the following vulnerability has been resolved: cpufreq/longhaul: handle NULL policy in longhaul_exit longhaul_exit() was calling…

PriorityP420high7.8
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: cpufreq/longhaul: handle NULL policy in longhaul_exit longhaul_exit() was calling cpufreq_cpu_get(0) without checking for a NULL policy pointer. On some systems, this could lead to a NULL dereference and a kernel warning or panic. This patch adds a check using unlikely() and returns early if the policy is NULL. Bugzilla: #219962

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2 < b02352dd2e6cca98777714cc2a27553191df70dbb02352dd2e6cca98777714cc2a27553191df70db
linuxlinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2 < 956b56d17a89775e4957bbddefa45cd3c6c71000956b56d17a89775e4957bbddefa45cd3c6c71000
linuxlinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2 < 55cf586b9556863e3c2a45460aba71bcb2be5bcd55cf586b9556863e3c2a45460aba71bcb2be5bcd
linuxlinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2 < fd93e1d71b3b14443092919be12b1abf08de35ebfd93e1d71b3b14443092919be12b1abf08de35eb
linuxlinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2 < 8d6791c480f22d6e9a566eaa77336d3d37c5c5918d6791c480f22d6e9a566eaa77336d3d37c5c591
linuxlinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2 < 64adabb6d9d51b7e7c02fe733346a2c4dd73848864adabb6d9d51b7e7c02fe733346a2c4dd738488
linuxlinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2 < 809cf2a7794ca4c14c304b349f4c3ae220701ce4809cf2a7794ca4c14c304b349f4c3ae220701ce4
linuxlinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2 < 592532a77b736b5153e0c2e4c74aa50af0a352ab592532a77b736b5153e0c2e4c74aa50af0a352ab
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 3.10.0 < 5.4.3025.4.302
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.5.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.