CVE-2025-38690

MEDIUM EPSS 2.8%
Published Sep 4, 20259mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Sep 4, 2025 9mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: prevent infinite recursion If the buf + offset is not aligned to XE_CAHELINE_BYTES we fallback to using a bounce buffer. However the bounce buffer here is allocated on the stack, and the only alignment requirement here is that it's naturally aligned to u8, and not XE_CACHELINE_BYTES. If the bounce buffer is also misaligned we then recurse back into the function again, however the new bounce buffer might also not be aligned, and might never be until we eventually blow through the stack, as we keep recursing. Instead of using the stack use kmalloc, which should respect the power-of-two alignment request here. Fixes a kernel panic when triggering this path through eudebug. v2 (Stuart): - Add build bug check for power-of-two restriction - s/EINVAL/ENOMEM/ (cherry picked from commit 38b34e928a08ba594c4bbf7118aa3aadacd62fff)

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-617

Affected Products 2

VendorProductVersionRange
linuxlinux_kernel*≥6.16  –  <6.16.2
linuxlinux_kernel6.17any

References 2

  • git.kernel.org https://git.kernel.org/stable/c/89f511c024879c5812cc0c010a6663b5e49950f3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9d7a1cbebbb691891671def57407ba2f8ee914e8
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/89f511c024879c5812cc0c010a6663b5e49950f3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9d7a1cbebbb691891671def57407ba2f8ee914e8
    Patch