PT-2025-29029 · Linux+1 · Linux Kernel+1

Anubis

·

Published

2025-05-14

·

Updated

2025-11-18

·

CVE-2025-38309

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains an issue within the drm/xe/vm subsystem. A flaw exists in the xe vm close and put() function where xe svm fini() can be called prematurely during virtual machine creation, specifically on error paths before the svm state is fully initialized. This can lead to system crashes (splats) and a non-recoverable NPD (Null Pointer Dereference) error.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

BDU:2025-09054
CVE-2025-38309

Affected Products

Astra Linux
Linux Kernel