cbcvebase.
CVE-2025-38408
published 2025-07-25

CVE-2025-38408: In the Linux kernel, the following vulnerability has been resolved: genirq/irq_sim: Initialize work context pointers properly Initialize `ops` member's…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.3th percentile
In the Linux kernel, the following vulnerability has been resolved: genirq/irq_sim: Initialize work context pointers properly Initialize `ops` member's pointers properly by using kzalloc() instead of kmalloc() when allocating the simulation work context. Otherwise the pointers contain random content leading to invalid dereferencing.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 < 186df821de0f34490ed5fc0861243748b2483861186df821de0f34490ed5fc0861243748b2483861
linuxlinux>= 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 < c71aa4bb528ae6f8fd7577a0a39e5a03c60b04fbc71aa4bb528ae6f8fd7577a0a39e5a03c60b04fb
linuxlinux>= 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 < ec3656a8cb428d763def32bc2fa695f94be23629ec3656a8cb428d763def32bc2fa695f94be23629
linuxlinux>= 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 < 19bd7597858dd15802c1d99fcc38e528f469080a19bd7597858dd15802c1d99fcc38e528f469080a
linuxlinux>= 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 < 7f73d1def72532bac4d55ea8838f457a6bed955c7f73d1def72532bac4d55ea8838f457a6bed955c
linuxlinux>= 337cbeb2c13eb4cab84f576fd402d7ae4ed31ae1 < 8a2277a3c9e4cc5398f80821afe7ecbe9bdf28198a2277a3c9e4cc5398f80821afe7ecbe9bdf2819
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.8 < 6.12.376.12.37
linuxlinux_kernel>= 6.13 < 6.15.66.15.6
msrcazl3_kernel_6.6.96.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-azure
ubuntulinux-azure-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.