SB2025050838 - NULL pointer dereference in Linux kernel cpufreq driver
Published: May 8, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-37831)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the apple_soc_cpufreq_get_rate() function in drivers/cpufreq/apple-soc-cpufreq.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/01e86ea22610d98ae6141e428019a6916e79f725
- https://git.kernel.org/stable/c/1053dcf8a504d4933bb3f73df22bc363298d194b
- https://git.kernel.org/stable/c/9992649f6786921873a9b89dafa5e04d8c5fef2b
- https://git.kernel.org/stable/c/fbdba5f37413dbc09d82ad7235e5b7a2fb8e0f75
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.26