PT-2025-34410 · Linux+4 · Linux Kernel+18

Published

2025-05-22

·

Updated

2025-12-15

·

CVE-2025-38649

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: An infinite loop in the Coresight devices, specifically within the coresight find activated sysfs sink function, can lead to a stack overflow and system crash. This occurs when only a source device is enabled, causing the function to recursively search for an active sink device. The affected components include replicator1 out, funnel swao in6, tmc etf swao in, tmc etf swao out, replicator1 in, replicator swao in, replicator0 out1, replicator0 in, funnel in1 in3, replicator swao out0, tmc etf out, tmc etf in, funnel merg out, funnel merg in1, and funnel in1 out. As a result of the fix, trace data can only originate from AOSS and reach the ETF SWAO and EUD sinks.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Recursion

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03085
CVE-2025-38649
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7934-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu
Funnel In1 In3
Funnel In1 Out
Funnel Merg In1
Funnel Merg Out
Funnel Swao In6
Replicator0 In
Replicator0 Out1
Replicator1 In
Replicator1 Out
Replicator Swao In
Replicator Swao Out0
Tmc Etf In
Tmc Etf Out
Tmc Etf Swao In
Tmc Etf Swao Out