PT-2025-29016 · Linux+3 · Linux Kernel+3

Published

2025-05-22

·

Updated

2025-12-03

·

CVE-2025-38296

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Name of the Vulnerable Software and Affected Versions:

Linux kernel versions 6.15.0-rc7 and earlier

Description:

The platform profile driver in the Linux kernel is loaded even on platforms without ACPI enabled. The initialization of sysfs entries was moved to the module init call, requiring acpi kobj to be initialized, which is not the case when ACPI is disabled. This results in a warning during system operation.

Recommendations:

Linux kernel versions prior to 6.15.0: Ensure ACPI is enabled before attempting to create sysfs entries.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08624
CVE-2025-38296
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7789-1
USN-7789-2

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu