PT-2025-27755 · Linux+6 · Linux Kernel+6

Published

2025-04-09

·

Updated

2026-04-20

·

CVE-2025-38170

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the handling of SME traps in the Linux kernel, specifically in the arm64/fpsimd component. The logic for handling SME traps manipulates saved FPSIMD/SVE/SME state incorrectly, and a race with preemption can result in a task having TIF SME set and TIF FOREIGN FPSTATE clear even though the live CPU state is stale. This can lead to warnings from do sme acc() where SME traps are not expected while TIF SME is set. The problem occurs when the SME trap handler is preempted before and after manipulating the saved FPSIMD/SVE/SME state, starting and ending on the same CPU.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

AZL-64625
BDU:2025-14100
CVE-2025-38170
DLA-4328-1
DSA-5973-1
ECHO-C02E-39AF-7A29
MGASA-2025-0218
MGASA-2025-0219
OESA-2025-1821
OESA-2025-1822
OESA-2025-1823
OESA-2025-1824
OESA-2025-1870
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7789-1
USN-7789-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu