CVE Database
/

CVE-2025-40346

Back to search

CVE-2025-40346

Published: Dec 16, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() Fix incorrect use of PTR_ERR_OR_ZERO() in topology_parse_cpu_capacity() which causes the code to proceed with NULL clock pointers. The current logic uses !PTR_ERR_OR_ZERO(cpu_clk) which evaluates to true for both valid pointers and NULL, leading to potential NULL pointer dereference in clk_get_rate(). Per include/linux/err.h documentation, PTR_ERR_OR_ZERO(ptr) returns: "The error code within @ptr if it is an error pointer; 0 otherwise." This means PTR_ERR_OR_ZERO() returns 0 for both valid pointers AND NULL pointers. Therefore !PTR_ERR_OR_ZERO(cpu_clk) evaluates to true (proceed) when cpu_clk is either valid or NULL, causing clk_get_rate(NULL) to be called when of_clk_get() returns NULL. Replace with !IS_ERR_OR_NULL(cpu_clk) which only proceeds for valid pointers, preventing potential NULL pointer dereference in clk_get_rate().

VendorProductVersions

Linux

Linux

affected
b8fe128dad8f97cc9af7c55a264d1fc5ab677195 - < 64da320252e43456cc9ec3055ff567f168467b37
affected
b8fe128dad8f97cc9af7c55a264d1fc5ab677195 - < 02fbea0864fd4a863671f5d418129258d7159f68
affected
b8fe128dad8f97cc9af7c55a264d1fc5ab677195 - < a77f8434954cb1e9c42c3854e40855fdcf5ab235
affected
b8fe128dad8f97cc9af7c55a264d1fc5ab677195 - < 3373f263bb647fcc3b5237cfaef757633b9ee25e
affected
b8fe128dad8f97cc9af7c55a264d1fc5ab677195 - < 45379303124487db3a81219af7565d41f498167f

+2 more versions

Linux

Linux

affected
5.7
unaffected
0 - < 5.7
unaffected
5.10.246 - <= 5.10.*
unaffected
5.15.196 - <= 5.15.*
unaffected
6.1.158 - <= 6.1.*

+4 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now