PT-2025-27722 · Linux+6 · Linux Kernel+6

Published

2025-04-07

·

Updated

2026-04-20

·

CVE-2025-38136

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.14.0-rc7+
Description: A vulnerability in the Linux kernel has been resolved, specifically in the renesas usbhs module. The issue arises from the incorrect ordering of clock handling and power management in the probe function, leading to potential crashes due to uninitialized clocks. The problematic call flow involves the usbhs probe() function, which accesses registers before enabling the clocks, resulting in a synchronous external abort on the RZ/V2H SoC. The estimated number of potentially affected devices is not provided.
Recommendations: For Linux kernel versions prior to 6.14.0-rc7+, update to a version that includes the fix for the renesas usbhs module, which reorders the initialization sequence in usbhs probe() to enable runtime PM before accessing registers. As a temporary workaround, consider disabling the usbhs probe() function until a patch is available. Restrict access to the renesas usbhs module to minimize the risk of exploitation.

Exploit

Fix

Use of Uninitialized Resource

Improper Initialization

Weakness Enumeration

Related Identifiers

AZL-64601
BDU:2025-09631
CVE-2025-38136
DLA-4327-1
DLA-4328-1
DSA-5973-1
ECHO-A812-4325-FAE0
MGASA-2025-0218
MGASA-2025-0219
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:02853-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:02969-1
SUSE-SU-2025:02996-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:03023-1
SUSE-SU-2025:20577-1
SUSE-SU-2025:20586-1
SUSE-SU-2025:20601-1
SUSE-SU-2025:20602-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02969-1
SUSE-SU-2025_02996-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
SUSE-SU-2025_03023-1
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7774-1
USN-7774-2
USN-7774-3
USN-7774-4
USN-7774-5
USN-7775-1
USN-7775-2
USN-7775-3
USN-7776-1
USN-7789-1
USN-7789-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu