CVE-2025-38565Linux vulnerability

21 documents8 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 96.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 19
Latest updateDec 16

Description

In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When perf_mmap() fails to allocate a buffer, it still invokes the event_mapped() callback of the related event. On X86 this might increase the perf_rdpmc_allowed reference counter. But nothing undoes this as perf_mmap_close() is never called in this case, which causes another reference count leak. Return early on failure to prevent that.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDlinux/linux_kernel4.05.4.297+7
Debianlinux/linux_kernel< 5.10.244-1+3
CVEListV5linux/linux1e0fb9ec679c9273a641f1d6f3d25ea47baef2bb5ffda7f3ed76ec8defc19d985e33b3b82ba07839+9

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

3
OSV
CVE-2025-38565: In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When perf_mmap() fails to allocate a buf2025-08-19
CVEList
perf/core: Exit early on perf_mmap() fail2025-08-19
GHSA
GHSA-j97q-xq86-pq24: In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When perf_mmap() fails to allocate a b2025-08-19

📋Vendor Advisories

17
Ubuntu
Linux kernel (Azure) vulnerabilities2025-12-16
Ubuntu
Linux kernel (Azure) vulnerabilities2025-12-15
Ubuntu
Linux kernel (KVM) vulnerabilities2025-12-15
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-12-15
Ubuntu
Linux kernel vulnerabilities2025-12-05
CVE-2025-38565 — Linux vulnerability | cvebase