cbcvebase.
CVE-2025-38489
published 2025-07-28

CVE-2025-38489: In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.5th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") has accidentally removed the critical piece of commit c730fce7c70c ("s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL"), causing intermittent kernel panics in e.g. perf's on_switch() prog to reappear. Restore the fix and add a comment.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.6.26 < 6.6.1006.6.100
linuxlinux>= 6.8.5 < 6.96.9
linuxlinux>= 7ded842b356d151ece8ac4985940438e6d3998bb < d5629d1af0600f8cc7c9245e8d832a66358ef889d5629d1af0600f8cc7c9245e8d832a66358ef889
linuxlinux>= 7ded842b356d151ece8ac4985940438e6d3998bb < a4f9c7846b1ac428921ce9676b1b8c80ed60093ca4f9c7846b1ac428921ce9676b1b8c80ed60093c
linuxlinux>= 7ded842b356d151ece8ac4985940438e6d3998bb < 6a5abf8cf182f577c7ae6c62f14debc9754ec9866a5abf8cf182f577c7ae6c62f14debc9754ec986
linuxlinux>= c3062bdb859b6e2567e7f5c8cde20c0250bb130f < 0c7b20f7785cfdd59403333612c90b458b12307c0c7b20f7785cfdd59403333612c90b458b12307c
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.41-16.12.41-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.13 < 6.15.86.15.8
linuxlinux_kernel>= 6.6.26 < 6.6.1006.6.100
linuxlinux_kernel>= 6.8.5 < 6.96.9
linuxlinux_kernel>= 6.9.1 < 6.12.406.12.40
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.