PT-2025-33762 · Linux+5 · Linux Kernel+5

Published

2025-07-30

·

Updated

2026-04-20

·

CVE-2025-38563

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The perf mmap code does not prevent Virtual Memory Area (VMA) splits caused by resizing or partial unmapping of a mapping. This can lead to reference count leaks in perf mmap open() and perf mmap close() calls, as subsequent calls do not fulfill offset and size checks. The issue occurs because the initial mapping's offset and size must match for subsequent mappings, and VMA splits violate this requirement. The vm operations struct::may split() callback is implemented to return -EINVAL, preventing VMA splits and ensuring mapping offsets and sizes remain unchanged after initial mapping.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

AZL-66494
AZL-73800
BDU:2025-10727
CVE-2025-38563
DLA-4327-1
DLA-4328-1
ECHO-A8B1-9AC7-C4AE
MGASA-2025-0234
MGASA-2025-0235
OESA-2025-2118
OESA-2025-2119
OESA-2025-2120
OESA-2025-2121
OESA-2025-2122
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03204-1
SUSE-SU-2025:03272-1
SUSE-SU-2025:03283-1
SUSE-SU-2025:03290-1
SUSE-SU-2025:03301-1
SUSE-SU-2025:03310-1
SUSE-SU-2025:03314-1
SUSE-SU-2025:03344-1
SUSE-SU-2025:03382-1
SUSE-SU-2025:03383-1
SUSE-SU-2025:03384-1
SUSE-SU-2025:03602-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20653-1
SUSE-SU-2025:20669-1
SUSE-SU-2025:20739-1
SUSE-SU-2025:20756-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_03204-1
SUSE-SU-2025_03272-1
SUSE-SU-2025_03290-1
SUSE-SU-2025_03301-1
SUSE-SU-2025_03310-1
SUSE-SU-2025_03314-1
SUSE-SU-2025_03344-1
SUSE-SU-2025_03382-1
SUSE-SU-2026:0474-1
SUSE-SU-2026:0475-1
SUSE-SU-2026:0495-1
SUSE-SU-2026:0496-1
SUSE-SU-2026:0617-1
SUSE-SU-2026:1131-1
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7934-1
USN-7938-1
ZDI-25-873

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu