PT-2025-33805 · Linux+1 · Linux Kernel+1

Published

2025-06-13

·

Updated

2025-11-26

·

CVE-2025-38607

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains an issue where the BPF JSET conditional jump is not correctly handled during control flow graph (CFG) computation. This can lead to incorrect live register and strongly connected component (SCC) calculations. Specifically, the can jump() function in verifier.c does not recognize BPF JSET as a jump instruction. This can cause the verifier to miss potential jump targets, leading to inaccurate register liveness analysis.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2026-02825
CVE-2025-38607

Affected Products

Astra Linux
Linux Kernel