PT-2025-35995 · Unknown+6 · Habanalabs+6

Published

2025-07-12

·

Updated

2026-04-20

·

CVE-2025-38722

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a use-after-free (UAF) vulnerability in the export dmabuf() function related to descriptor table management. Specifically, a file reference could be inserted into the descriptor table and then closed by another thread before it is fully initialized, leading to a UAF condition when accessing objects destroyed on close. The dma buf fd() function, used in habanalabs export dmabuf(), is susceptible to this issue as it combines descriptor reservation and fd install(). The fix involves reserving the descriptor before any other operations and performing fd install() only after complete setup.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

AZL-66881
BDU:2026-02850
CVE-2025-38722
ECHO-2B76-3B16-90B0
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03601-1
SUSE-SU-2025:03602-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3725-1
SUSE-SU-2025:3751-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Habanalabs