PT-2025-30755 · Linux+3 · Linux Kernel+3

Published

2025-07-25

·

Updated

2025-11-25

·

CVE-2025-38355

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s DRM/XE subsystem related to the handling of GGTT node removals during device unwinding. Specifically, the issue arises when deferred GGTT node removals occur after the MMIO/GMS mapping has been released, potentially leading to page faults and kernel crashes. This was observed during unsuccessful VF initialization, resulting in a bug where the system was unable to handle a page fault due to a supervisor write access in kernel mode. The root cause is the asynchronous removal of GGTT nodes and the order in which operations are performed during device unwinding.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15217
CVE-2025-38355
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:02853-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1

Affected Products

Linuxmint
Linux Kernel
Suse
Ubuntu