PT-2025-28889 · Linux+3 · Linux Kernel+3
CVE-2025-38261
·
Published
2025-07-09
·
Updated
2026-08-30
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions 5.12.0-rc2-syzkaller-00467-g0d7588ab9ef9 and earlier.
Description:
A flaw exists in the Linux kernel's task switching routine on RISC-V architecture. Specifically, the issue relates to the handling of the SR SUM status during thread/task switching. Without proper saving and restoring of the SR SUM state, crashes can occur, particularly under heavy load conditions, such as those generated by the syz-stress tool. The root cause is related to the
put user() macro within the schedule tail() function, which could lead to a panic when interacting with sleeping functions.Recommendations:
Linux kernel versions prior to 5.12.0-rc2-syzkaller-00467-g0d7588ab9ef9 should be updated.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Ubuntu