CVE-2025-38386

MEDIUM EPSS 6.2%
Published Jul 25, 202511mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 25, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Refuse to evaluate a method if arguments are missing As reported in [1], a platform firmware update that increased the number of method parameters and forgot to update a least one of its callers, caused ACPICA to crash due to use-after-free. Since this a result of a clear AML issue that arguably cannot be fixed up by the interpreter (it cannot produce missing data out of thin air), address it by making ACPICA refuse to evaluate a method if the caller attempts to pass fewer arguments than expected to it.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
6.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 10

VendorProductVersionRange
linuxlinux_kernel* <5.4.296
linuxlinux_kernel*≥5.5  –  <5.10.240
linuxlinux_kernel*≥5.11  –  <5.15.187
linuxlinux_kernel*≥5.16  –  <6.1.144
linuxlinux_kernel*≥6.2  –  <6.6.97
linuxlinux_kernel*≥6.7  –  <6.12.37
linuxlinux_kernel*≥6.13  –  <6.15.6
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
debiandebian_linux11.0any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/18ff4ed6a33a7e3f2097710eacc96bea7696e803
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2219e49857ffd6aea1b1ca5214d3270f84623a16
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4305d936abde795c2ef6ba916de8f00a50f64d2d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6fcab2791543924d438e7fa49276d0998b0a069f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ab1e8491c19eb2ea0fda81ef28e841c7cb6399f5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b49d224d1830c46e20adce2a239c454cdab426f1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9e4da550ae196132b990bd77ed3d8f2d9747f87
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d547779e72cea9865b732cd45393c4cd02b3598e
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
    Third Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Third Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/18ff4ed6a33a7e3f2097710eacc96bea7696e803
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2219e49857ffd6aea1b1ca5214d3270f84623a16
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4305d936abde795c2ef6ba916de8f00a50f64d2d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6fcab2791543924d438e7fa49276d0998b0a069f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ab1e8491c19eb2ea0fda81ef28e841c7cb6399f5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b49d224d1830c46e20adce2a239c454cdab426f1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9e4da550ae196132b990bd77ed3d8f2d9747f87
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d547779e72cea9865b732cd45393c4cd02b3598e
    Patch