cbcvebase.
CVE-2025-38386
published 2025-07-25

CVE-2025-38386: In the Linux kernel, the following vulnerability has been resolved: ACPICA: Refuse to evaluate a method if arguments are missing As reported in [1], a platform…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: ACPICA: Refuse to evaluate a method if arguments are missing As reported in [1], a platform firmware update that increased the number of method parameters and forgot to update a least one of its callers, caused ACPICA to crash due to use-after-free. Since this a result of a clear AML issue that arguably cannot be fixed up by the interpreter (it cannot produce missing data out of thin air), address it by making ACPICA refuse to evaluate a method if the caller attempts to pass fewer arguments than expected to it.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b49d224d1830c46e20adce2a239c454cdab426f1b49d224d1830c46e20adce2a239c454cdab426f1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2219e49857ffd6aea1b1ca5214d3270f84623a162219e49857ffd6aea1b1ca5214d3270f84623a16
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ab1e8491c19eb2ea0fda81ef28e841c7cb6399f5ab1e8491c19eb2ea0fda81ef28e841c7cb6399f5
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4305d936abde795c2ef6ba916de8f00a50f64d2d4305d936abde795c2ef6ba916de8f00a50f64d2d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d547779e72cea9865b732cd45393c4cd02b3598ed547779e72cea9865b732cd45393c4cd02b3598e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 18ff4ed6a33a7e3f2097710eacc96bea7696e80318ff4ed6a33a7e3f2097710eacc96bea7696e803
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c9e4da550ae196132b990bd77ed3d8f2d9747f87c9e4da550ae196132b990bd77ed3d8f2d9747f87
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6fcab2791543924d438e7fa49276d0998b0a069f6fcab2791543924d438e7fa49276d0998b0a069f
linuxlinux_kernel< 5.4.2965.4.296
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 5.15.0-156.1665.15.0-156.166
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.11 < 5.15.1875.15.187
linuxlinux_kernel>= 5.16 < 6.1.1446.1.144
linuxlinux_kernel>= 5.5 < 5.10.2405.10.240
linuxlinux_kernel>= 6.13 < 6.15.66.15.6
linuxlinux_kernel>= 6.2 < 6.6.976.6.97

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM