cbcvebase.
CVE-2025-38341
published 2025-07-10

CVE-2025-38341: In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: avoid double free when failing to DMA-map FW msg The semantics are that caller…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: avoid double free when failing to DMA-map FW msg The semantics are that caller of fbnic_mbx_map_msg() retains the ownership of the message on error. All existing callers dutifully free the page.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
linuxlinux
linuxlinux>= da3cde08209ec1c915195c2331c275397f34a731 < 670179265ad787b9dd8e701601914618b8927755670179265ad787b9dd8e701601914618b8927755
linuxlinux>= da3cde08209ec1c915195c2331c275397f34a731 < 0a211e23852019ef55c70094524e87a944accbb50a211e23852019ef55c70094524e87a944accbb5
linuxlinux>= da3cde08209ec1c915195c2331c275397f34a731 < 5bd1bafd4474ee26f504b41aba11f3e2a1175b885bd1bafd4474ee26f504b41aba11f3e2a1175b88
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 6.11 < 6.12.356.12.35
linuxlinux_kernel>= 6.13 < 6.15.46.15.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.