CVE-2025-38195
published 2025-07-04CVE-2025-38195: In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Unable to…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()
ERROR INFO:
CPU 25 Unable to handle kernel paging request at virtual address 0x0
...
Call Trace:
[] huge_pte_offset+0x3c/0x58
[] hugetlb_follow_page_mask+0x74/0x438
[] __get_user_pages+0xe0/0x4c8
[] faultin_page_range+0x84/0x380
[] madvise_vma_behavior+0x534/0xa48
[] do_madvise+0x1bc/0x3e8
[] sys_madvise+0x24/0x38
[] do_syscall+0x78/0x98
[] handle_syscall+0xb8/0x158
In some cases, pmd may be NULL and rely on NULL as the return value for
processing, so it is necessary to determine this situation here.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.12.35-1 (forky) | linux 6.12.35-1 (forky) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 2ca9380b12711afe95b3589bd82b59623b3c96b3 < b427d98d55217b53c88643579fbbd8a4c351a105 | b427d98d55217b53c88643579fbbd8a4c351a105 |
| linux | linux | >= 51424fd171cee6a33f01f7c66b8eb23ac42289d4 < 985f086f281b7bbb6644851e63af1a17ffff9277 | 985f086f281b7bbb6644851e63af1a17ffff9277 |
| linux | linux | >= 6.1.136 < 6.2 | 6.2 |
| linux | linux | >= 6.12.26 < 6.12.35 | 6.12.35 |
| linux | linux | >= 6.14.5 < 6.15 | 6.15 |
| linux | linux | >= 6.6.89 < 6.6.95 | 6.6.95 |
| linux | linux | >= bd51834d1cf65a2c801295d230c220aeebf87a73 < b5c7397b7fd125203c60b59860c168ee92291272 | b5c7397b7fd125203c60b59860c168ee92291272 |
| linux | linux | >= bd51834d1cf65a2c801295d230c220aeebf87a73 < ee084fa96123ede8b0563a1b5a9b23adc43cd50d | ee084fa96123ede8b0563a1b5a9b23adc43cd50d |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.12.35-1 | 6.12.35-1 |
| linux | linux_kernel | >= 0 < 6.12.35-1 | 6.12.35-1 |
| linux | linux_kernel | >= 6.1.136 < 6.2 | 6.2 |
| linux | linux_kernel | >= 6.12.26 < 6.12.35 | 6.12.35 |
| linux | linux_kernel | >= 6.14.5 < 6.15 | 6.15 |
| linux | linux_kernel | >= 6.15.1 < 6.15.4 | 6.15.4 |
| linux | linux_kernel | >= 6.6.89 < 6.6.95 | 6.6.95 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-38195: In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Un
osv·2025-07-04·CVSS 5.5
CVE-2025-38195 [MEDIUM] CVE-2025-38195: In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Un
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Unable to handle kernel paging request at virtual address 0x0 ... Call Trace: [] huge_pte_offset+0x3c/0x58 [] hugetlb_follow_page_mask+0x74/0x438 [] __get_user_pages+0xe0/0x4c8 [] faultin_page_range+0x84/0x380 [] madvise_vma_behavior+0x534/0xa48 [] do_madvise+0x1bc/0x3e8 [] sys_madvise+0x24/0x38 [] do_syscall+0x78/0x98 [] handle_syscall+0xb8/0x158 In some cases, pmd may be NULL and rely on NULL as the return value for processing, so it is necessary to determine this situation here.
GHSA
GHSA-qffh-4j5f-8w7g: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()
ERROR INFO:
CPU 25
ghsa_unreviewed·2025-07-04
CVE-2025-38195 [MEDIUM] GHSA-qffh-4j5f-8w7g: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()
ERROR INFO:
CPU 25
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()
ERROR INFO:
CPU 25 Unable to handle kernel paging request at virtual address 0x0
...
Call Trace:
[] huge_pte_offset+0x3c/0x58
[] hugetlb_follow_page_mask+0x74/0x438
[] __get_user_pages+0xe0/0x4c8
[] faultin_page_range+0x84/0x380
[] madvise_vma_behavior+0x534/0xa48
[] do_madvise+0x1bc/0x3e8
[] sys_madvise+0x24/0x38
[] do_syscall+0x78/0x98
[] handle_syscall+0xb8/0x158
In some cases, pmd may be NULL and rely on NULL as the return value for
processing, so it is necessary to determine this situation here.
Red Hat
kernel: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()
vendor_redhat·2025-07-04·CVSS 5.5
CVE-2025-38195 [MEDIUM] kernel: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()
kernel: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()
ERROR INFO:
CPU 25 Unable to handle kernel paging request at virtual address 0x0
...
Call Trace:
[] huge_pte_offset+0x3c/0x58
[] hugetlb_follow_page_mask+0x74/0x438
[] __get_user_pages+0xe0/0x4c8
[] faultin_page_range+0x84/0x380
[] madvise_vma_behavior+0x534/0xa48
[] do_madvise+0x1bc/0x3e8
[] sys_madvise+0x24/0x38
[] do_syscall+0x78/0x98
[] handle_syscall+0xb8/0x158
In some cases, pmd may be NULL and rely on NULL as the return value for
processing, so it is necessary to determine this situation here.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterpr
Debian
CVE-2025-38195: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...
vendor_debian·2025·CVSS 5.5
CVE-2025-38195 [MEDIUM] CVE-2025-38195: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Unable to handle kernel paging request at virtual address 0x0 ... Call Trace: [] huge_pte_offset+0x3c/0x58 [] hugetlb_follow_page_mask+0x74/0x438 [] __get_user_pages+0xe0/0x4c8 [] faultin_page_range+0x84/0x380 [] madvise_vma_behavior+0x534/0xa48 [] do_madvise+0x1bc/0x3e8 [] sys_madvise+0x24/0x38 [] do_syscall+0x78/0x98 [] handle_syscall+0xb8/0x158 In some cases, pmd may be NULL and rely on NULL as the return value for processing, so it is necessary to determine this situation here.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.12.35-1)
sid: resolved (fixed in 6.12.35-1)
trixie: resolved (fixed in 6.12.35-1)
No detection rules found.
No public exploits indexed.
2025-07-04
Published