PT-2025-30869 · Linux+5 · Linux Kernel+5
Published
2025-01-01
·
Updated
2026-04-20
·
CVE-2025-38455
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.15.0-smp-DEV #2
Description
The Linux kernel contained a flaw within the KVM component, specifically related to Secure Encrypted Virtualization (SEV) and Secure Encrypted Virtualization-Encrypted State (SEV-ES). The vulnerability allowed for potential issues during intra-host migration if a virtual CPU (vCPU) was being created concurrently. Specifically, the issue could lead to a non-SEV-ES vCPU being created within an SEV-ES VM, potentially resulting in a crash when attempting to free the vCPU's Virtual Machine State Area (VMSA) page. This could also lead to other unpredictable behavior.
Recommendations
Update to Linux kernel version 6.15.0-smp-DEV #2 or a later version to address this issue.
Exploit
Fix
NULL Pointer Dereference
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu