CVE-2025-38489
MEDIUMLinux Kernel 6.6.26-6.6.99, 6.7.0-6.12.39, 6.9.0-6.15.7 - NULL Pointer Dereference in BPF Text Poke
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") has accidentally removed the critical piece of commit c730fce7c70c ("s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL"), causing intermittent kernel panics in e.g. perf's on_switch() prog to reappear. Restore the fix and add a comment.
References (4)
Core 4
Core References
Scores
CVSS v3
5.5
EPSS
0.0013
EPSS Percentile
3.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (19)
linux/Kernel
< 6.6.100linux
linux/Kernel
6.7.0 - 6.12.40linux
linux/Kernel
6.9.0 - 6.15.8linux
Linux/Linux
< 6.9
Linux/Linux
6.12.40 - 6.12.*
Linux/Linux
6.15.8 - 6.15.*
Linux/Linux
6.16
Linux/Linux
6.6.100 - 6.6.*
Linux/Linux
6.6.26 - 6.6.100
Linux/Linux
6.8.5 - 6.9
... and 9 more
Published
Jul 28, 2025
Tracked Since
Feb 18, 2026