CVE-2025-38297 – Linux PM: EM Division-by-Zero Vulnerability

The following table lists the changes that have been made to the
CVE-2025-38297 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 10, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    PM: EM: Fix potential division-by-zero error in em_compute_costs()

    When the device is of a non-CPU type, table[i].performance won’t be
    initialized in the previous em_init_performance(), resulting in division
    by zero when calculating costs in em_compute_costs().

    Since the ‘cost’ algorithm is only used for EAS energy efficiency
    calculations and is currently not utilized by other device drivers, we
    should add the _is_cpu_device(dev) check to prevent this division-by-zero
    issue.

    Added Reference https://git.kernel.org/stable/c/14cbdd64f3870cf0a2d94b87919b9056448c59a0
    Added Reference https://git.kernel.org/stable/c/179c0c7044a378198adb36f2a12410ab68cc730a
    Added Reference https://git.kernel.org/stable/c/81d72f9241d884ec29524431f74f8009310cfa0c
Share the Post:

Related Posts