cbcvebase.
CVE-2025-38421
published 2025-07-25

CVE-2025-38421: In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: pmf: Use device managed allocations If setting up smart PC fails for any…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: pmf: Use device managed allocations If setting up smart PC fails for any reason then this can lead to a double free when unloading amd-pmf. This is because dev->buf was freed but never set to NULL and is again freed in amd_pmf_remove(). To avoid subtle allocation bugs in failures leading to a double free change all allocations into device managed allocations.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5b1122fc4995f308b21d7cfc64ef9880ac834d20 < 0d10b532f861253c283863522d59d099fcb0796d0d10b532f861253c283863522d59d099fcb0796d
linuxlinux>= 5b1122fc4995f308b21d7cfc64ef9880ac834d20 < d9db3a941270d92bbd1a6a6b54a10324484f2f2dd9db3a941270d92bbd1a6a6b54a10324484f2f2d
linuxlinux>= 6.12.23 < 6.136.13
linuxlinux>= 6.13.11 < 6.146.14
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 6.12.23 < 6.136.13
linuxlinux_kernel>= 6.13.11 < 6.146.14
linuxlinux_kernel>= 6.14.1 < 6.15.46.15.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.