In the Linux kernel, the following vulnerability has been resolved:
security: Restrict CONFIG_ZERO_CALL_USED_REGS to gcc or clang > 15.0.6
A bad bug in clang's implementation of -fzero-call-used-regs can result in NULL pointer dereferences (see the links above the check for more information). Restrict CONFIG_CC_HAS_ZERO_CALL_USED_REGS to either a supported GCC version or a clang newer than 15.0.6, which will catch both a theoretical 15.0.7 and the upcoming 16.0.0, which will both have the bug fixed.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Ubuntu | — | Upgrade linux-oracleUpgrade linux-nvidiaUpgrade linux-gkeopUpgrade linux-oracle-5.15Upgrade linux-ibmUpgrade linux-gkeUpgrade linuxUpgrade linux-lowlatencyUpgrade linux-azure-fde-5.15Upgrade linux-azure-5.15Upgrade linux-gcpUpgrade linux-awsUpgrade linux-azureUpgrade linux-raspiUpgrade linux-intel-iotg-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-hwe-5.15Upgrade linux-intel-iotgUpgrade linux-kvmUpgrade linux-intel-iot-realtimeUpgrade linux-gcp-5.15Upgrade linux-bluefieldUpgrade linux-nvidia-tegra-5.15Upgrade linux-realtimeUpgrade linux-aws-5.15Upgrade linux-riscv-5.15 | Jan 6, 2026 | Jan 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub