CVE-2025-38195

MEDIUM

Linux Kernel - NULL Pointer Dereference in huge_pte_offset()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Unable to handle kernel paging request at virtual address 0x0 ... Call Trace: [<900000000023c30c>] huge_pte_offset+0x3c/0x58 [<900000000057fd4c>] hugetlb_follow_page_mask+0x74/0x438 [<900000000051fee8>] __get_user_pages+0xe0/0x4c8 [<9000000000522414>] faultin_page_range+0x84/0x380 [<9000000000564e8c>] madvise_vma_behavior+0x534/0xa48 [<900000000056689c>] do_madvise+0x1bc/0x3e8 [<9000000000566df4>] sys_madvise+0x24/0x38 [<90000000015b9e88>] do_syscall+0x78/0x98 [<9000000000221f18>] handle_syscall+0xb8/0x158 In some cases, pmd may be NULL and rely on NULL as the return value for processing, so it is necessary to determine this situation here.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (21)
linux/Kernel < 6.6.95linux
linux/Kernel 6.13.0 - 6.15.4linux
linux/Kernel 6.7.0 - 6.12.35linux
Linux/Linux < 6.15
Linux/Linux 2ca9380b12711afe95b3589bd82b59623b3c96b3 - b427d98d55217b53c88643579fbbd8a4c351a105
Linux/Linux 34256805720993e37adf6127371a1265aea8376a
Linux/Linux 51424fd171cee6a33f01f7c66b8eb23ac42289d4 - 985f086f281b7bbb6644851e63af1a17ffff9277
Linux/Linux 6.1.136 - 6.2
Linux/Linux 6.12.26 - 6.12.35
Linux/Linux 6.12.35 - 6.12.*
... and 11 more
Published Jul 04, 2025
Tracked Since Feb 18, 2026