PT-2025-27896 · Linux+3 · Linux Kernel+3

Published

2025-05-24

·

Updated

2025-12-03

·

CVE-2025-38175

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.15.0-rc7-00138-g57483a362741
Description: A use-after-free vulnerability has been identified in the Linux kernel, specifically in the binder devices list. The issue arises when devices are released without being removed from the list, allowing for potential exploitation. The vulnerability was addressed by ensuring that the device is removed from the binder devices list before being freed.
Recommendations: For Linux kernel versions prior to 6.15.0-rc7-00138-g57483a362741, update to a version that includes the fix for the use-after-free vulnerability in the binder devices list. As a temporary workaround, consider restricting access to the binder remove device function until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08220
CVE-2025-38175
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7789-1
USN-7789-2

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu