PT-2025-30774 · Linux+5 · Linux Kernel+5

Published

2025-06-02

·

Updated

2026-04-20

·

CVE-2025-38374

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The OP-TEE driver registers the notif callback() function for FF-A notifications. This function is called in an atomic context, which can lead to errors when processing asynchronous notifications, specifically a kernel BUG related to sleeping in an invalid context. The issue occurs when processing notifications via the ffa pcpu irq notification workqueue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2025-09145
CVE-2025-38374
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Op-Tee
Suse
Ubuntu