CVE-2025-38408

MEDIUM

Linux Kernel - NULL Pointer Dereference in IRQ Simulation Work Context

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: genirq/irq_sim: Initialize work context pointers properly Initialize `ops` member's pointers properly by using kzalloc() instead of kmalloc() when allocating the simulation work context. Otherwise the pointers contain random content leading to invalid dereferencing.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (21)
linux/Kernel 5.16.0 - 6.1.162linux
linux/Kernel 5.8.0 - 5.15.199linux
linux/Kernel 6.13.0 - 6.15.6linux
linux/Kernel 6.2.0 - 6.6.120linux
linux/Kernel 6.7.0 - 6.12.37linux
Linux/Linux < 5.8
Linux/Linux 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 - 186df821de0f34490ed5fc0861243748b2483861
Linux/Linux 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 - 19bd7597858dd15802c1d99fcc38e528f469080a
Linux/Linux 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 - 7f73d1def72532bac4d55ea8838f457a6bed955c
Linux/Linux 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 - 8a2277a3c9e4cc5398f80821afe7ecbe9bdf2819
... and 11 more
Published Jul 25, 2025
Tracked Since Feb 18, 2026