cbcvebase.
CVE-2025-38586
published 2025-08-19

CVE-2025-38586: In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix fp initialization for exception boundary In the ARM64 BPF JIT when…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
6.0th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix fp initialization for exception boundary In the ARM64 BPF JIT when prog->aux->exception_boundary is set for a BPF program, find_used_callee_regs() is not called because for a program acting as exception boundary, all callee saved registers are saved. find_used_callee_regs() sets `ctx->fp_used = true;` when it sees FP being used in any of the instructions. For programs acting as exception boundary, ctx->fp_used remains false even if frame pointer is used by the program and therefore, FP is not set-up for such programs in the prologue. This can cause the kernel to crash due to a pagefault. Fix it by setting ctx->fp_used = true for exception boundary programs as fp is always saved in such programs.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux>= 5d4fa9ec5643a5c75d3c1e6abf50fb9284caf1ff < 0dbef493cae7d451f740558665893c000adb23210dbef493cae7d451f740558665893c000adb2321
linuxlinux>= 5d4fa9ec5643a5c75d3c1e6abf50fb9284caf1ff < e23184725dbb72d5d02940222eee36dbba2aa422e23184725dbb72d5d02940222eee36dbba2aa422
linuxlinux>= 5d4fa9ec5643a5c75d3c1e6abf50fb9284caf1ff < 1ce30231e0a2c8c361ee5f8f7f265fc17130adce1ce30231e0a2c8c361ee5f8f7f265fc17130adce
linuxlinux>= 5d4fa9ec5643a5c75d3c1e6abf50fb9284caf1ff < b114fcee766d5101eada1aca7bb5fd0a86c89b35b114fcee766d5101eada1aca7bb5fd0a86c89b35
linuxlinux_kernel>= 0 < 6.12.43-16.12.43-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 6.12 < 6.12.426.12.42
linuxlinux_kernel>= 6.13 < 6.15.106.15.10
linuxlinux_kernel>= 6.16 < 6.16.16.16.1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.