PT-2025-27964 · Linux+4 · Linux Kernel+4

CVE-2025-38189

·

Publicado

2025-06-02

·

Atualizado

2026-08-25

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to the fixed version
Description: A NULL pointer dereference issue in the v3d job update stats() function has been identified. This issue occurs when a file descriptor is closed before the jobs submitted by it are completed, resulting in an attempt to update the per-fd GPU stats after the struct v3d file priv and its stats have been freed. The issue is associated with a kernel Oops and can lead to a fatal exception in interrupt.
Recommendations: To resolve this issue, update the Linux kernel to a version that includes the fix for the NULL pointer dereference in the v3d job update stats() function. As a temporary workaround, consider avoiding the closure of file descriptors before the completion of submitted jobs to minimize the risk of exploitation.

Exploit

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-09618
CVE-2025-38189
ECHO-E4E5-0352-DFF1
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:02853-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
SUSE-SU-2026:20560-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1

Produtos afetados

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu