PT-2025-34390 · Linux+5 · Linux Kernel+5
Published
2025-07-08
·
Updated
2026-03-24
·
CVE-2025-38628
CVSS v2.0
5.7
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A flaw exists in the Linux kernel's vdpa/mlx5 component related to the release of uninitialized resources during error handling. Specifically, the
mlx5 vdpa destroy mr resources() and mlx5 cmd cleanup async ctx() functions were unable to handle uninitialized resources, leading to a kernel splat when adding a vdpa device without a MAC address. The fix ensures that mlx5 vdpa free() is the single entry point for removing vdpa device resources, even in cleanup paths, and that all called functions can handle uninitialized resources.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu