CVE-2025-68177

UnknownEPSS 0.18%

Last modified

CVE-2025-68177 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: cpufreq/longhaul: handle NULL policy in longhaul_exit longhaul_exit() was calling cpufreq_cpu_get(0) without checking for a NULL policy pointer. On some systems, this could lead to a NULL dereference and a kernel warning or panic. This patch adds a check using unlikely() and returns early if the policy is NULL. Bugzilla: #219962. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: cpufreq/longhaul: handle NULL policy in longhaul_exit longhaul_exit() was calling cpufreq_cpu_get(0) without checking for a NULL policy pointer. On some systems, this could lead to a NULL dereference and a kernel warning or panic. This patch adds a check using unlikely() and returns early if the policy is NULL. Bugzilla: #219962

Metrics

EPSS Probability
0.18%

7.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2, < b02352dd2e6cca98777714cc2a27553191df70db; >= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2, < 956b56d17a89775e4957bbddefa45cd3c6c71000; >= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2, < 55cf586b9556863e3c2a45460aba71bcb2be5bcd; >= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2, < fd93e1d71b3b14443092919be12b1abf08de35eb; >= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2, < 8d6791c480f22d6e9a566eaa77336d3d37c5c591; >= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2, < 64adabb6d9d51b7e7c02fe733346a2c4dd738488; >= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2, < 809cf2a7794ca4c14c304b349f4c3ae220701ce4; >= b43a7ffbf33be7e4d3b10b7714ee663ea2c52fe2, < 592532a77b736b5153e0c2e4c74aa50af0a352ab
LinuxLinux3.10

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-68177?
In the Linux kernel, the following vulnerability has been resolved: cpufreq/longhaul: handle NULL policy in longhaul_exit longhaul_exit() was calling cpufreq_cpu_get(0) without checking for a NULL policy pointer. On some systems, this could lead to a NULL dereference and a kernel warning or panic. This patch adds a check using unlikely() and returns early if the policy is NULL. Bugzilla: #219962
How severe is CVE-2025-68177?
Severity scoring for CVE-2025-68177 is pending analysis. The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2025-68177?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-68177?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST