PT-2025-27964 · Linux+4 · Linux Kernel+4
Published
2025-06-02
·
Updated
2026-04-20
·
CVE-2025-38189
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to the fixed version
Description:
A NULL pointer dereference issue in the
v3d job update stats() function has been identified. This issue occurs when a file descriptor is closed before the jobs submitted by it are completed, resulting in an attempt to update the per-fd GPU stats after the struct v3d file priv and its stats have been freed. The issue is associated with a kernel Oops and can lead to a fatal exception in interrupt.Recommendations:
To resolve this issue, update the Linux kernel to a version that includes the fix for the NULL pointer dereference in the
v3d job update stats() function. As a temporary workaround, consider avoiding the closure of file descriptors before the completion of submitted jobs to minimize the risk of exploitation.Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu