CVE-2025-38609

Source
https://cve.org/CVERecord?id=CVE-2025-38609
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38609.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38609
Downstream
Related
Published
2025-08-19T17:03:52.542Z
Modified
2026-05-28T03:53:44.777980876Z
Summary
PM / devfreq: Check governor before using governor->name
Details

In the Linux kernel, the following vulnerability has been resolved:

PM / devfreq: Check governor before using governor->name

Commit 96ffcdf239de ("PM / devfreq: Remove redundant governorname from struct devfreq") removes governorname and uses governor->name to replace it. But devfreq->governor may be NULL and directly using devfreq->governor->name may cause null pointer exception. Move the check of governor to before using governor->name.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38609.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
96ffcdf239de6f9970178bb7d643e16fd9e68ab9
Fixed
f0479e878d4beb45e73c03e574c59f0a23ccd176
Fixed
631e101728df2a86b8fb761b49fad9712c651f8a
Fixed
81f50619370045120c133bfdda5b320c8c97d41e
Fixed
d5632359dbc44862fc1ed04093c1f57529830261
Fixed
2731c68f536fddcb71332db7f8d78c5eb4684c04
Fixed
75323a49aa603cf5484a6d74d0d329e86d756e11
Fixed
bab7834c03820eb11269bc48f07c3800192460d2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38609.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.190
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.148
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.102
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.42
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.10
Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.16.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38609.json"