CVE-2025-38364

MEDIUM EPSS 5.3%
Published Jul 25, 202511mo ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 25, 2025 11mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: maple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate() Temporarily clear the preallocation flag when explicitly requesting allocations. Pre-existing allocations are already counted against the request through mas_node_count_gfp(), but the allocations will not happen if the MA_STATE_PREALLOC flag is set. This flag is meant to avoid re-allocating in bulk allocation mode, and to detect issues with preallocation calculations. The MA_STATE_PREALLOC flag should also always be set on zero allocations so that detection of underflow allocations will print a WARN_ON() during consumption. User visible effect of this flaw is a WARN_ON() followed by a null pointer dereference when subsequent requests for larger number of nodes is ignored, such as the vma merge retry in mmap_region() caused by drivers altering the vma flags (which happens in v6.6, at least)

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
5.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 8

VendorProductVersionRange
linuxlinux_kernel*≥6.1  –  <6.1.146
linuxlinux_kernel*≥6.2  –  <6.6.99
linuxlinux_kernel*≥6.7  –  <6.12.36
linuxlinux_kernel*≥6.13  –  <6.15.5
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
debiandebian_linux11.0any

References 7

  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-082556.html
  • git.kernel.org https://git.kernel.org/stable/c/9e32f4700867abbd5d19abfcf698dbd0d2ce36a4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cf95f8426f889949b738f51ffcd72884411f3a6a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d69cd64bd5af41c6fd409313504089970edaf02f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e63032e66bca1d06e600033f3369ba3db3af0870
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fba46a5d83ca8decb338722fb4899026d8d9ead2
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Third Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/9e32f4700867abbd5d19abfcf698dbd0d2ce36a4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cf95f8426f889949b738f51ffcd72884411f3a6a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d69cd64bd5af41c6fd409313504089970edaf02f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e63032e66bca1d06e600033f3369ba3db3af0870
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fba46a5d83ca8decb338722fb4899026d8d9ead2
    Patch