CVE-2025-38489

MEDIUM

Linux Kernel 6.6.26-6.6.99, 6.7.0-6.12.39, 6.9.0-6.15.7 - NULL Pointer Dereference in BPF Text Poke

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") has accidentally removed the critical piece of commit c730fce7c70c ("s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL"), causing intermittent kernel panics in e.g. perf's on_switch() prog to reappear. Restore the fix and add a comment.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (19)
linux/Kernel < 6.6.100linux
linux/Kernel 6.7.0 - 6.12.40linux
linux/Kernel 6.9.0 - 6.15.8linux
Linux/Linux < 6.9
Linux/Linux 6.12.40 - 6.12.*
Linux/Linux 6.15.8 - 6.15.*
Linux/Linux 6.16
Linux/Linux 6.6.100 - 6.6.*
Linux/Linux 6.6.26 - 6.6.100
Linux/Linux 6.8.5 - 6.9
... and 9 more
Published Jul 28, 2025
Tracked Since Feb 18, 2026