PT-2025-28880 · Linux+1 · Linux Kernel+1

Anubis

·

Published

2025-07-09

·

Updated

2025-07-09

·

CVE-2025-38252

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The cxl cper handle prot err() function makes assumptions about the type and binding of devices identified in records, potentially leading to crashes. Specifically, the function incorrectly assumes endpoints are CXL-type-3 devices and bound to the cxl pci driver. The code has been corrected to verify that the PCIe endpoint parents a cxl memdev before assuming the driver data format, preparing the implementation for CXL accelerators not bound to cxl pci.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2025-13464
CVE-2025-38252

Affected Products

Astra Linux
Linux Kernel