CVE-2025-38187
published 2025-07-04CVE-2025-38187: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is released…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
The RPC container is released after being passed to r535_gsp_rpc_send().
When sending the initial fragment of a large RPC and passing the
caller's RPC container, the container will be freed prematurely. Subsequent
attempts to send remaining fragments will therefore result in a
use-after-free.
Allocate a temporary RPC container for holding the initial fragment of a
large RPC when sending. Free the caller's container when all fragments
are successfully sent.
[ Rebase onto Blackwell changes. - Danilo ]
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.16.3-1 (forky) | linux 6.16.3-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 176fdcbddfd288408ce8571c1760ad618d962096 < cd4677407c0ee250fc21e36439c8a442ddd62cc1 | cd4677407c0ee250fc21e36439c8a442ddd62cc1 |
| linux | linux | >= 176fdcbddfd288408ce8571c1760ad618d962096 < 9802f0a63b641f4cddb2139c814c2e95cb825099 | 9802f0a63b641f4cddb2139c814c2e95cb825099 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.16.3-1 | 6.16.3-1 |
| linux | linux_kernel | >= 6.7 < 6.15.4 | 6.15.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
vendor_redhat·2025-07-04·CVSS 7.8
CVE-2025-38187 [HIGH] kernel: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
kernel: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
The RPC container is released after being passed to r535_gsp_rpc_send().
When sending the initial fragment of a large RPC and passing the
caller's RPC container, the container will be freed prematurely. Subsequent
attempts to send remaining fragments will therefore result in a
use-after-free.
Allocate a temporary RPC container for holding the initial fragment of a
large RPC when sending. Free the caller's container when all fragments
are successfully sent.
[ Rebase onto Blackwell changes. - Danilo ]
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux
Debian
CVE-2025-38187: linux - In the Linux kernel, the following vulnerability has been resolved: drm/nouveau...
vendor_debian·2025·CVSS 7.8
CVE-2025-38187 [HIGH] CVE-2025-38187: linux - In the Linux kernel, the following vulnerability has been resolved: drm/nouveau...
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is released after being passed to r535_gsp_rpc_send(). When sending the initial fragment of a large RPC and passing the caller's RPC container, the container will be freed prematurely. Subsequent attempts to send remaining fragments will therefore result in a use-after-free. Allocate a temporary RPC container for holding the initial fragment of a large RPC when sending. Free the caller's container when all fragments are successfully sent. [ Rebase onto Blackwell changes. - Danilo ]
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.16.3-1)
sid: resolved (fixed in 6.16.3-1)
trixie: open
VulDB
Linux Kernel up to 6.15.3/6.16-rc2 nouveau r535_gsp_rpc_push use after free (EUVD-2025-20069 / Nessus ID 253428)
vuldb·2026-07-31·CVSS 7.8
CVE-2025-38187 [HIGH] Linux Kernel up to 6.15.3/6.16-rc2 nouveau r535_gsp_rpc_push use after free (EUVD-2025-20069 / Nessus ID 253428)
A vulnerability marked as critical has been reported in Linux Kernel up to 6.15.3/6.16-rc2. Impacted is the function r535_gsp_rpc_push of the component nouveau. Performing a manipulation results in use after free.
This vulnerability was named CVE-2025-38187. The attack needs to be approached within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
OSV
CVE-2025-38187: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is rele
osv·2025-07-04·CVSS 7.8
CVE-2025-38187 [HIGH] CVE-2025-38187: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is rele
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is released after being passed to r535_gsp_rpc_send(). When sending the initial fragment of a large RPC and passing the caller's RPC container, the container will be freed prematurely. Subsequent attempts to send remaining fragments will therefore result in a use-after-free. Allocate a temporary RPC container for holding the initial fragment of a large RPC when sending. Free the caller's container when all fragments are successfully sent. [ Rebase onto Blackwell changes. - Danilo ]
GHSA
GHSA-pf92-pqjf-2hmw: In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
The RPC container is re
ghsa_unreviewed·2025-07-04
CVE-2025-38187 [HIGH] CWE-416 GHSA-pf92-pqjf-2hmw: In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
The RPC container is re
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
The RPC container is released after being passed to r535_gsp_rpc_send().
When sending the initial fragment of a large RPC and passing the
caller's RPC container, the container will be freed prematurely. Subsequent
attempts to send remaining fragments will therefore result in a
use-after-free.
Allocate a temporary RPC container for holding the initial fragment of a
large RPC when sending. Free the caller's container when all fragments
are successfully sent.
[ Rebase onto Blackwell changes. - Danilo ]
No detection rules found.
No public exploits indexed.
2025-07-04
Published