CVE-2025-38479

HIGH

Linux Kernel 6.11-6.12.22, 6.13.0-6.13.10, 6.14.0-6.14.1 - Denial of Service via DMA Engine IRQ Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: free irq correctly in remove path Add fsl_edma->txirq/errirq check to avoid below warning because no errirq at i.MX9 platform. Otherwise there will be kernel dump: WARNING: CPU: 0 PID: 11 at kernel/irq/devres.c:144 devm_free_irq+0x74/0x80 Modules linked in: CPU: 0 UID: 0 PID: 11 Comm: kworker/u8:0 Not tainted 6.12.0-rc7#18 Hardware name: NXP i.MX93 11X11 EVK board (DT) Workqueue: events_unbound deferred_probe_work_func pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : devm_free_irq+0x74/0x80 lr : devm_free_irq+0x48/0x80 Call trace: devm_free_irq+0x74/0x80 (P) devm_free_irq+0x48/0x80 (L) fsl_edma_remove+0xc4/0xc8 platform_remove+0x28/0x44 device_remove+0x4c/0x80

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 17.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (14)
linux/Kernel 6.11.0 - 6.12.23linux
linux/Kernel 6.13.0 - 6.13.11linux
linux/Kernel 6.14.0 - 6.14.2linux
Linux/Linux < 6.11
Linux/Linux 44eb827264de4f14d8317692441e13f5e2aadbf2 - 38ff8769074db27387cb2323aaa751e59d168e6a
Linux/Linux 44eb827264de4f14d8317692441e13f5e2aadbf2 - 55e2dbe2ba787d4fc2306f6bb2f43fb32176e184
Linux/Linux 44eb827264de4f14d8317692441e13f5e2aadbf2 - f3834d2d68749e4760c27325149765930ad876fd
Linux/Linux 44eb827264de4f14d8317692441e13f5e2aadbf2 - fa70c4c3c580c239a0f9e83a14770ab026e8d820
Linux/Linux 6.11
Linux/Linux 6.12.23 - 6.12.*
... and 4 more
Published Apr 18, 2025
Tracked Since Feb 18, 2026