PT-2025-17272 · Nxp+9 · I.Mx9+10

Published

2025-03-22

·

Updated

2026-04-20

·

CVE-2025-38152

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.14.0-rc7-next-20250317
Description A vulnerability in the Linux kernel has been resolved. The issue occurs when using U-Boot to start a remote processor with a resource table published to a fixed address, then stopping the processor, loading new firmware without a resource table, and restarting the processor. This can trigger a kernel dump due to a NULL pointer dereference. The issue is found on i.MX8MP and i.MX9 devices.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the vulnerability. As a temporary workaround, consider disabling the rproc start function until a patch is available. Restrict access to the vulnerable remoteproc module to minimize the risk of exploitation. Avoid using the rproc shutdown function with firmware that does not have a resource table until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
ALT-PU-2025-7195
BDU:2025-12113
CVE-2025-38152
DLA-4193-1
DSA-5907-1
ECHO-F048-7023-F3F5
MGASA-2025-0142
MGASA-2025-0146
OESA-2025-1729
OESA-2025-1730
OESA-2025-1870
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
SUSE-SU-2025_02000-1
USN-7591-1
USN-7591-2
USN-7591-3
USN-7591-4
USN-7591-5
USN-7591-6
USN-7592-1
USN-7593-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7597-1
USN-7597-2
USN-7598-1
USN-7602-1
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7655-1
USN-7835-1
USN-7835-2
USN-7835-3
USN-7835-4
USN-7835-5
USN-7835-6
USN-7887-1
USN-7887-2
USN-7940-1
USN-7940-2

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
U-Boot
Ubuntu
I.Mx8Mp
I.Mx9