SB20250509109 - NULL pointer dereference in Linux kernel cpupower bench
Published: May 9, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-37841)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the prepare_default_config() function in tools/power/cpupower/bench/parse.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0e297a02e03dceb2874789ca40bd4e65c5371704
- https://git.kernel.org/stable/c/208baa3ec9043a664d9acfb8174b332e6b17fb69
- https://git.kernel.org/stable/c/34a9394794b0f97af6afedc0c9ee2012c24b28ed
- https://git.kernel.org/stable/c/5e38122aa3fd0f9788186e86a677925bfec0b2d1
- https://git.kernel.org/stable/c/79bded9d70142d2a11d931fc029afece471641db
- https://git.kernel.org/stable/c/87b9f0867c0afa7e892f4b30c36cff6bf2707f85
- https://git.kernel.org/stable/c/942a4b97fc77516678b1d8af1521ff9a94c13b3e
- https://git.kernel.org/stable/c/ceec06f464d5cfc0ba966225f7d50506ceb62242
- https://git.kernel.org/stable/c/f8d28fa305b78c5d1073b63f26db265ba8291ae1
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.24