CVE-2025-38469
MEDIUMLinux Kernel 6.2.1-6.6.99, 6.7.0-6.12.39, 6.13.0-6.15.7 - Use-After-Free in KVM Xen Schedop Poll Hypercall Emulation
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host for more than one event channel potr (nr_ports > 1). After the kmalloc_array(), the error paths need to go through the "out" label, but the call to kvm_read_guest_virt() does not. [Adjusted commit message. - Paolo]
References (4)
Core 4
Core References
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
4.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (16)
linux/Kernel
6.13.0 - 6.15.8linux
linux/Kernel
6.2.0 - 6.6.100linux
linux/Kernel
6.7.0 - 6.12.40linux
Linux/Linux
< 6.2
Linux/Linux
6.12.40 - 6.12.*
Linux/Linux
6.15.8 - 6.15.*
Linux/Linux
6.16
Linux/Linux
6.2
Linux/Linux
6.6.100 - 6.6.*
Linux/Linux
92c58965e9656dc6e682a8ffe520fac0fb256d13 - 061c553c66bc1638c280739999224c8000fd4602
... and 6 more
Published
Jul 28, 2025
Tracked Since
Feb 18, 2026