CVE-2025-38095 — NULL Pointer Dereference in Linux
Severity
5.5MEDIUMNVD
OSV7.8OSV3.2
EPSS
0.0%
top 86.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3
Latest updateMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
dma-buf: insert memory barrier before updating num_fences
smp_store_mb() inserts memory barrier after storing operation.
It is different with what the comment is originally aiming so Null
pointer dereference can be happened if memory update is reordered.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
▶CVEListV5linux/linuxa590d0fdbaa56f482ff515e1040b6d9b1b200d63 — 90eb79c4ed98a4e24a62ccf61c199ab0f680fa8f+7
Also affects: Debian Linux 11.0