PT-2025-30840 · Linux+1 · Linux Kernel+1
Published
2025-05-30
·
Updated
2025-07-25
·
CVE-2025-38433
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The
runtime fixup 32 function does not correctly handle cases where val is zero, potentially leading to an invalid pointer and a kernel panic when accessing it. This occurs because the logic allows the emission of two nop instructions, leaving garbage in a register intended to hold the upper 32 bits of a pointer. The issue arises from incomplete logic following the conversion of a lui instruction into a nop.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Insufficiently Random Values
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel