CVE-2025-38351 — Improper Check for Unusual or Exceptional Conditions in Linux
Severity
5.5MEDIUMNVD
OSV3.2
EPSS
0.0%
top 91.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 19
Latest updateMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush
In KVM guests with Hyper-V hypercalls enabled, the hypercalls
HVCALL_FLUSH_VIRTUAL_ADDRESS_LIST and HVCALL_FLUSH_VIRTUAL_ADDRESS_LIST_EX
allow a guest to request invalidation of portions of a virtual TLB.
For this, the hypercall parameter includes a list of GVAs that are supposed
to be invalidated.
However, when non-canonical GVAs are passed, there is currentl…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages15 packages
Patches
🔴Vulnerability Details
24📋Vendor Advisories
24💬Community
1Bugzilla▶
CVE-2025-38351 kernel: KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush↗2025-07-19