PT-2025-33805 · Linux+1 · Linux Kernel+1
Published
2025-06-13
·
Updated
2025-11-26
·
CVE-2025-38607
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The Linux kernel contains an issue where the BPF JSET conditional jump is not correctly handled during control flow graph (CFG) computation. This can lead to incorrect live register and strongly connected component (SCC) calculations. Specifically, the
can jump() function in verifier.c does not recognize BPF JSET as a jump instruction. This can cause the verifier to miss potential jump targets, leading to inaccurate register liveness analysis.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel