PT-2025-35969 · Linux+4 · Linux Kernel+4

Published

2025-06-11

·

Updated

2026-04-20

·

CVE-2025-38696

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw where stack top() may crash for tasks lacking an ABI or vDSO. This occurs because the code attempts to dereference a NULL ABI pointer when called by tasks, such as kthreads, that do not have an ABI associated with them or a vDSO mapped. The issue can be triggered, for example, when using kunit. The fix ensures the ABI pointer is only dereferenced if it is set, and also includes the GIC page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-66797
BDU:2025-15758
CVE-2025-38696
DLA-4328-1
DSA-6009-1
ECHO-5062-29BF-D9A5
MGASA-2025-0234
MGASA-2025-0235
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu