Database/Control plane, storage & DevOps
Linux cpufreq/amd-pstate - missing NULL check in amd_pstate_update: amd_pstate_update() dereferences the cpufreq policy
CVSS 5.5CVE-2025-23137Control plane, storage & DevOpscurated
Impact
amd_pstate_update() dereferences the cpufreq policy without checking it for NULL, panicking the host. The CPU frequency driver runs constantly on every AMD node, so a NULL dereference here takes the machine down and every GPU job on it with no warning and no attacker involvement.
Who can reach it
Local, on the amd-pstate update path. Reachable through normal frequency-governor activity.
What to do
Distro kernel update plus reboot; no firmware step.
References
Related entries
- Linux x86/CPU/AMD - INVLPGB on Zen 2 (Cyan Skillfish): Using broadcast TLB invalidation (INVLPGB) on affected Zen 2CVE-2025-38518 · Linux x86/CPU/AMD - INVLPGB on Zen 2 (Cyan Skillfish)Medium
- SPDK (Storage Performance Development Kit) 25.05 - NVMe-oF target, lib/nvmf: A buffer overflow in the NVMe-oF targetCVE-2025-57275 · SPDK (Storage Performance Development Kit) 25.05 - NVMe-oF target, lib/nvmfMedium
- HashiCorp go-slug: Unicode normalization mismatch lets excluded files slip past .terraformignore into the uploadCVE-2026-14978 · HashiCorp go-slug (.terraformignore path matching, Unicode normalization)Medium
- IBM Storage Scale management GUI (deploy and upgrade logging): The Storage Scale admin password is written in the clearCVE-2026-19483 · IBM Storage Scale management GUI (deploy and upgrade logging)Medium
- Linux kernel CephFS client: invalid kfree() when listing .snap directories oopses the nodeCVE-2026-23201 · Linux kernel CephFS client (parse_longname snapshot handling)Medium
- Linux perf/x86 - event pointer setup ordering in x86_pmu_enable(): A NULL pointer dereference in the x86 PMU enableCVE-2026-23435 · Linux perf/x86 - event pointer setup ordering in x86_pmu_enable()Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.