cbcvebase.
CVE-2025-38095
published 2025-07-03

CVE-2025-38095: In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_fences smp_store_mb() inserts memory…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_fences smp_store_mb() inserts memory barrier after storing operation. It is different with what the comment is originally aiming so Null pointer dereference can be happened if memory update is reordered.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux>= a590d0fdbaa56f482ff515e1040b6d9b1b200d63 < 90eb79c4ed98a4e24a62ccf61c199ab0f680fa8f90eb79c4ed98a4e24a62ccf61c199ab0f680fa8f
linuxlinux>= a590d0fdbaa56f482ff515e1040b6d9b1b200d63 < d0b7f11dd68b593bd970e5735be00e8d89bace30d0b7f11dd68b593bd970e5735be00e8d89bace30
linuxlinux>= a590d0fdbaa56f482ff515e1040b6d9b1b200d63 < 3becc659f9cb76b481ad1fb71f54d5c8d6332d3f3becc659f9cb76b481ad1fb71f54d5c8d6332d3f
linuxlinux>= a590d0fdbaa56f482ff515e1040b6d9b1b200d63 < c9d2b9a80d06a58f37e0dc8c827075639b443927c9d2b9a80d06a58f37e0dc8c827075639b443927
linuxlinux>= a590d0fdbaa56f482ff515e1040b6d9b1b200d63 < fe1bebd0edb22e3536cbc920ec713331d1367ad4fe1bebd0edb22e3536cbc920ec713331d1367ad4
linuxlinux>= a590d0fdbaa56f482ff515e1040b6d9b1b200d63 < 08680c4dadc6e736c75bc2409d833f03f9003c5108680c4dadc6e736c75bc2409d833f03f9003c51
linuxlinux>= a590d0fdbaa56f482ff515e1040b6d9b1b200d63 < 72c7d62583ebce7baeb61acce6057c361f73be4a72c7d62583ebce7baeb61acce6057c361f73be4a
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.30-16.12.30-1
linuxlinux_kernel>= 0 < 6.12.30-16.12.30-1
linuxlinux_kernel>= 0 < 5.15.0-163.1735.15.0-163.173
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.0 < 5.10.2415.10.241
linuxlinux_kernel>= 5.11 < 5.15.1925.15.192

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.