PT-2025-33551 · Linux+4 · Linux Kernel+4

Published

2025-06-30

·

Updated

2025-12-15

·

CVE-2025-38508

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains a flaw related to Secure TSC frequency calculation in SEV-SNP VMs. The GUEST TSC FREQ MSR reports a frequency based on the nominal P0 frequency, which deviates from the actual mean TSC frequency. This discrepancy accumulates over time, causing clock skew between the hypervisor and the guest VM, leading to early timer interrupts. The guest kernel relies on the reported nominal frequency for timekeeping, while the actual frequency may differ, resulting in inaccurate time calculations. The issue is addressed by utilizing the TSC FACTOR from the SEV firmware's secrets page to calculate the mean TSC frequency, ensuring accurate timekeeping. The fix also involves using early ioremap encrypted() to map the secrets page.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10446
CVE-2025-38508
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7934-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu