Microsoft Security Response Center guidance
Vendor revision: Aug 12, 2026CBL-Mariner Releases
Vendor-listed releases
- 5.15.180.1-1
- 6.6.92.2-1
Vulnerability intelligence
CVE-2025-23136 and is rated Medium severity with a CVSS score of 5.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
Vendor-listed releases
In the Linux kernel, the following vulnerability has been resolved:
thermal: int340x: Add NULL check for adev
Not all devices have an ACPI companion fwnode, so adev might be NULL. This is similar to the commit cd2fd6eab480 ("platform/x86: int3472: Check for adev == NULL").
Add a check for adev not being set and return -ENODEV in that case to avoid a possible NULL pointer deref in int3402_thermal_probe().
Note, under the same directory, int3400_thermal_probe() has such a check.
[ rjw: Subject edit, added Fixes: ]
Source: NVD