cbcvebase.
CVE-2025-38597
published 2025-08-19

CVE-2025-38597: In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port Each window of…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
5.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port Each window of a vop2 is usable by a specific set of video ports, so while binding the vop2, we look through the list of available windows trying to find one designated as primary-plane and usable by that specific port. The code later wants to use drm_crtc_init_with_planes with that found primary plane, but nothing has checked so far if a primary plane was actually found. For whatever reason, the rk3576 vp2 does not have a usable primary window (if vp0 is also in use) which brought the issue to light and ended in a null-pointer dereference further down. As we expect a primary-plane to exist for a video-port, add a check at the end of the window-iteration and fail probing if none was found.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux>= 604be85547ce4d61b89292d2f9a78c721b778c16 < e1eef239399927b368f70a716044fb10085627c8e1eef239399927b368f70a716044fb10085627c8
linuxlinux>= 604be85547ce4d61b89292d2f9a78c721b778c16 < 38682edbbad272b5f8c7bf55128b42cd10626f7338682edbbad272b5f8c7bf55128b42cd10626f73
linuxlinux>= 604be85547ce4d61b89292d2f9a78c721b778c16 < f9f68bf1d0efeadb6c427c9dbb30f307a7def19bf9f68bf1d0efeadb6c427c9dbb30f307a7def19b
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 5.19 < 6.15.106.15.10
linuxlinux_kernel>= 6.16 < 6.16.16.16.1
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.