PT-2025-27964 · Linux+4 · Linux Kernel+4

Published

2025-06-02

·

Updated

2026-04-20

·

CVE-2025-38189

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to the fixed version
Description: A NULL pointer dereference issue in the v3d job update stats() function has been identified. This issue occurs when a file descriptor is closed before the jobs submitted by it are completed, resulting in an attempt to update the per-fd GPU stats after the struct v3d file priv and its stats have been freed. The issue is associated with a kernel Oops and can lead to a fatal exception in interrupt.
Recommendations: To resolve this issue, update the Linux kernel to a version that includes the fix for the NULL pointer dereference in the v3d job update stats() function. As a temporary workaround, consider avoiding the closure of file descriptors before the completion of submitted jobs to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-09618
CVE-2025-38189
ECHO-E4E5-0352-DFF1
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:02853-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu