cbcvebase.
CVE-2025-38429
published 2025-07-25

CVE-2025-38429: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Update read pointer only after buffer is written Inside…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.38%
30.7th percentile
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Update read pointer only after buffer is written Inside mhi_ep_ring_add_element, the read pointer (rd_offset) is updated before the buffer is written, potentially causing race conditions where the host sees an updated read pointer before the buffer is actually written. Updating rd_offset prematurely can lead to the host accessing an uninitialized or incomplete element, resulting in data corruption. Invoke the buffer write before updating rd_offset to ensure the element is fully written before signaling its availability.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
linuxlinux
linuxlinux>= bbdcba57a1a26a4439a4f4ecdbfaf80a10fd8f34 < 44b9620e82bbec2b9a6ac77f63913636d84f96dc44b9620e82bbec2b9a6ac77f63913636d84f96dc
linuxlinux>= bbdcba57a1a26a4439a4f4ecdbfaf80a10fd8f34 < f704a80d9fa268e51a6cc5242714502c3c1fa605f704a80d9fa268e51a6cc5242714502c3c1fa605
linuxlinux>= bbdcba57a1a26a4439a4f4ecdbfaf80a10fd8f34 < 0007ef098dab48f1ba58364c40b4809f1e21b1300007ef098dab48f1ba58364c40b4809f1e21b130
linuxlinux>= bbdcba57a1a26a4439a4f4ecdbfaf80a10fd8f34 < 6f18d174b73d0ceeaa341f46c0986436b3aefc9a6f18d174b73d0ceeaa341f46c0986436b3aefc9a
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.19 < 6.6.956.6.95
linuxlinux_kernel>= 6.13 < 6.15.46.15.4
linuxlinux_kernel>= 6.7 < 6.12.356.12.35
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.122.1-2_on_cbl_mariner_2.0
msrccm1_kernel_5.10.188.1-1_on_cbl_mariner_1.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime
ubuntulinux-realtime

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM
vendor_msrc9.8CRITICAL
vendor_ubuntu5.6MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.