PT-2025-34390 · Linux+5 · Linux Kernel+5

Published

2025-07-08

·

Updated

2026-03-24

·

CVE-2025-38628

CVSS v2.0

5.7

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A flaw exists in the Linux kernel's vdpa/mlx5 component related to the release of uninitialized resources during error handling. Specifically, the mlx5 vdpa destroy mr resources() and mlx5 cmd cleanup async ctx() functions were unable to handle uninitialized resources, leading to a kernel splat when adding a vdpa device without a MAC address. The fix ensures that mlx5 vdpa free() is the single entry point for removing vdpa device resources, even in cleanup paths, and that all called functions can handle uninitialized resources.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15786
CVE-2025-38628
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03601-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3725-1
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7934-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu