cbcvebase.
CVE-2025-38195
published 2025-07-04

CVE-2025-38195: In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Unable to…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset() ERROR INFO: CPU 25 Unable to handle kernel paging request at virtual address 0x0 ... Call Trace: [] huge_pte_offset+0x3c/0x58 [] hugetlb_follow_page_mask+0x74/0x438 [] __get_user_pages+0xe0/0x4c8 [] faultin_page_range+0x84/0x380 [] madvise_vma_behavior+0x534/0xa48 [] do_madvise+0x1bc/0x3e8 [] sys_madvise+0x24/0x38 [] do_syscall+0x78/0x98 [] handle_syscall+0xb8/0x158 In some cases, pmd may be NULL and rely on NULL as the return value for processing, so it is necessary to determine this situation here.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2ca9380b12711afe95b3589bd82b59623b3c96b3 < b427d98d55217b53c88643579fbbd8a4c351a105b427d98d55217b53c88643579fbbd8a4c351a105
linuxlinux>= 51424fd171cee6a33f01f7c66b8eb23ac42289d4 < 985f086f281b7bbb6644851e63af1a17ffff9277985f086f281b7bbb6644851e63af1a17ffff9277
linuxlinux>= 6.1.136 < 6.26.2
linuxlinux>= 6.12.26 < 6.12.356.12.35
linuxlinux>= 6.14.5 < 6.156.15
linuxlinux>= 6.6.89 < 6.6.956.6.95
linuxlinux>= bd51834d1cf65a2c801295d230c220aeebf87a73 < b5c7397b7fd125203c60b59860c168ee92291272b5c7397b7fd125203c60b59860c168ee92291272
linuxlinux>= bd51834d1cf65a2c801295d230c220aeebf87a73 < ee084fa96123ede8b0563a1b5a9b23adc43cd50dee084fa96123ede8b0563a1b5a9b23adc43cd50d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 6.1.136 < 6.26.2
linuxlinux_kernel>= 6.12.26 < 6.12.356.12.35
linuxlinux_kernel>= 6.14.5 < 6.156.15
linuxlinux_kernel>= 6.15.1 < 6.15.46.15.4
linuxlinux_kernel>= 6.6.89 < 6.6.956.6.95

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.