CVE-2025-38469
MEDIUM EPSS 4.4%
Published Jul 28, 202511mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Published Jul 28, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host for more than one event channel potr (nr_ports > 1). After the kmalloc_array(), the error paths need to go through the "out" label, but the call to kvm_read_guest_virt() does not. [Adjusted commit message. - Paolo]
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
4.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Affected Products 18
| Vendor | Product | Version | Range |
|---|---|---|---|
| linux | linux_kernel | * | ≥6.2.1 – <6.6.100 |
| linux | linux_kernel | * | ≥6.7 – <6.12.40 |
| linux | linux_kernel | * | ≥6.13 – <6.15.8 |
| linux | linux_kernel | 6.2 | any |
| linux | linux_kernel | 6.2 | any |
| linux | linux_kernel | 6.2 | any |
| linux | linux_kernel | 6.2 | any |
| linux | linux_kernel | 6.2 | any |
| linux | linux_kernel | 6.2 | any |
| linux | linux_kernel | 6.2 | any |
| linux | linux_kernel | 6.2 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
References 4
- git.kernel.org https://git.kernel.org/stable/c/061c553c66bc1638c280739999224c8000fd4602
- git.kernel.org https://git.kernel.org/stable/c/3ee59c38ae7369ad1f7b846e05633ccf0d159fab
- git.kernel.org https://git.kernel.org/stable/c/5a53249d149f48b558368c5338b9921b76a12f8c
- git.kernel.org https://git.kernel.org/stable/c/fd627ac8a5cff4d45269f164b13ddddc0726f2cc
Remediation
- git.kernel.org https://git.kernel.org/stable/c/061c553c66bc1638c280739999224c8000fd4602
- git.kernel.org https://git.kernel.org/stable/c/3ee59c38ae7369ad1f7b846e05633ccf0d159fab
- git.kernel.org https://git.kernel.org/stable/c/5a53249d149f48b558368c5338b9921b76a12f8c
- git.kernel.org https://git.kernel.org/stable/c/fd627ac8a5cff4d45269f164b13ddddc0726f2cc