CVE-2025-38469

MEDIUM

Linux Kernel 6.2.1-6.6.99, 6.7.0-6.12.39, 6.13.0-6.15.7 - Use-After-Free in KVM Xen Schedop Poll Hypercall Emulation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host for more than one event channel potr (nr_ports > 1). After the kmalloc_array(), the error paths need to go through the "out" label, but the call to kvm_read_guest_virt() does not. [Adjusted commit message. - Paolo]

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (16)
linux/Kernel 6.13.0 - 6.15.8linux
linux/Kernel 6.2.0 - 6.6.100linux
linux/Kernel 6.7.0 - 6.12.40linux
Linux/Linux < 6.2
Linux/Linux 6.12.40 - 6.12.*
Linux/Linux 6.15.8 - 6.15.*
Linux/Linux 6.16
Linux/Linux 6.2
Linux/Linux 6.6.100 - 6.6.*
Linux/Linux 92c58965e9656dc6e682a8ffe520fac0fb256d13 - 061c553c66bc1638c280739999224c8000fd4602
... and 6 more
Published Jul 28, 2025
Tracked Since Feb 18, 2026