CVE-2025-38239

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2025
Last modified:
18/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> scsi: megaraid_sas: Fix invalid node index<br /> <br /> On a system with DRAM interleave enabled, out-of-bound access is<br /> detected:<br /> <br /> megaraid_sas 0000:3f:00.0: requested/available msix 128/128 poll_queue 0<br /> ------------[ cut here ]------------<br /> UBSAN: array-index-out-of-bounds in ./arch/x86/include/asm/topology.h:72:28<br /> index -1 is out of range for type &amp;#39;cpumask *[1024]&amp;#39;<br /> dump_stack_lvl+0x5d/0x80<br /> ubsan_epilogue+0x5/0x2b<br /> __ubsan_handle_out_of_bounds.cold+0x46/0x4b<br /> megasas_alloc_irq_vectors+0x149/0x190 [megaraid_sas]<br /> megasas_probe_one.cold+0xa4d/0x189c [megaraid_sas]<br /> local_pci_probe+0x42/0x90<br /> pci_device_probe+0xdc/0x290<br /> really_probe+0xdb/0x340<br /> __driver_probe_device+0x78/0x110<br /> driver_probe_device+0x1f/0xa0<br /> __driver_attach+0xba/0x1c0<br /> bus_for_each_dev+0x8b/0xe0<br /> bus_add_driver+0x142/0x220<br /> driver_register+0x72/0xd0<br /> megasas_init+0xdf/0xff0 [megaraid_sas]<br /> do_one_initcall+0x57/0x310<br /> do_init_module+0x90/0x250<br /> init_module_from_file+0x85/0xc0<br /> idempotent_init_module+0x114/0x310<br /> __x64_sys_finit_module+0x65/0xc0<br /> do_syscall_64+0x82/0x170<br /> entry_SYSCALL_64_after_hwframe+0x76/0x7e<br /> <br /> Fix it accordingly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.17 (including) 6.1.143 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.96 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.15.5 (excluding)
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*