PT-2025-28890 · Linux+4 · Linux Kernel+4

Anubis

·

Published

2025-07-09

·

Updated

2026-05-26

·

CVE-2025-38262

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A concurrency race condition can occur when two instances of uart devices are probing. If one thread calls the uart register driver function, which allocates memory for the uart state member of the uart driver structure, the other instance can bypass driver registration and call ulite assign. This calls uart add one port, expecting the driver to be fully initialized, leading to a kernel panic due to a null pointer dereference. The issue is resolved by moving uart driver registration into the init function to ensure the driver is always registered when the probe function is called.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-64853
AZL-72799
BDU:2025-13467
CVE-2025-38262
DLA-4328-1
DSA-5973-1
ECHO-9C8B-D548-8A45
MGASA-2025-0218
MGASA-2025-0219
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
USN-7774-1
USN-7774-2
USN-7774-3
USN-7774-4
USN-7774-5
USN-7775-1
USN-7775-2
USN-7775-3
USN-7776-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu