CVE-2025-38227Use After Free in Linux

CWE-416Use After Free55 documents8 sources
Severity
7.8HIGHNVD
OSV7.1OSV5.6
EPSS
0.0%
top 91.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 4
Latest updateJan 9

Description

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of initialization failure syzbot reported a slab-use-after-free Read in vidtv_mux_init. [1] After PSI initialization fails, the si member is accessed again, resulting in this uaf. After si initialization fails, the subsequent process needs to be exited. [1] BUG: KASAN: slab-use-after-free in vidtv_mux_pid_ctx_init drivers/media/test-drivers/vidtv/vidtv_mux.c:78 [inline] BUG:

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel5.10.15.10.239+6
Debianlinux/linux_kernel< 5.10.244-1+3
Ubuntulinux/linux_kernel< 5.15.0-156.166+1
CVEListV5linux/linux3be8037960bccd13052cfdeba8805ad785041d70e1d72ff111eceea6b28dccb7ca4e8f4900b11729+7

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

28
OSV
linux-azure-nvidia vulnerabilities2026-01-09
OSV
linux-azure-fips vulnerabilities2025-12-17
OSV
linux-raspi, linux-raspi-realtime, linux-xilinx vulnerabilities2025-12-16
OSV
linux-azure, linux-azure-6.8 vulnerabilities2025-12-15
OSV
linux-hwe-6.8, linux-oracle-6.8 vulnerabilities2025-12-11

📋Vendor Advisories

26
Ubuntu
Linux kernel (Azure, N-Series) vulnerabilities2026-01-09
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2025-12-17
Ubuntu
Linux kernel vulnerabilities2025-12-16
Ubuntu
Linux kernel (Azure) vulnerabilities2025-12-15
Ubuntu
Linux kernel vulnerabilities2025-12-11
CVE-2025-38227 — Use After Free in Linux | cvebase