cbcvebase.
CVE-2025-38360
published 2025-07-25

CVE-2025-38360: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add more checks for DSC / HUBP ONO guarantees [WHY] For non-zero DSC…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
5.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add more checks for DSC / HUBP ONO guarantees [WHY] For non-zero DSC instances it's possible that the HUBP domain required to drive it for sequential ONO ASICs isn't met, potentially causing the logic to the tile to enter an undefined state leading to a system hang. [HOW] Add more checks to ensure that the HUBP domain matching the DSC instance is appropriately powered. (cherry picked from commit da63df07112e5a9857a8d2aaa04255c4206754ec)

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.37-1 (forky)linux 6.12.37-1 (forky)
linuxlinux
linuxlinux>= 6f8b7565cca4b745da54b7d5f26b7b9265a5f330 < 646442758910d13f9afc57f38bc0a537c3575390646442758910d13f9afc57f38bc0a537c3575390
linuxlinux>= 6f8b7565cca4b745da54b7d5f26b7b9265a5f330 < 3f4e601bc6765e4ff5f42cc2d00993c86b367f7e3f4e601bc6765e4ff5f42cc2d00993c86b367f7e
linuxlinux>= 6f8b7565cca4b745da54b7d5f26b7b9265a5f330 < 0d57dd1765d311111d9885346108c4deeae1deb40d57dd1765d311111d9885346108c4deeae1deb4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 6.13 < 6.15.56.15.5
linuxlinux_kernel>= 6.7 < 6.12.376.12.37

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM
vendor_ubuntu5.6MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.