CVE-2025-38510

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
16/08/2025
Last modified:
07/01/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> kasan: remove kasan_find_vm_area() to prevent possible deadlock<br /> <br /> find_vm_area() couldn&amp;#39;t be called in atomic_context. If find_vm_area() is<br /> called to reports vm area information, kasan can trigger deadlock like:<br /> <br /> CPU0 CPU1<br /> vmalloc();<br /> alloc_vmap_area();<br /> spin_lock(&amp;vn-&gt;busy.lock)<br /> spin_lock_bh(&amp;some_lock);<br /> <br /> <br /> spin_lock(&amp;some_lock);<br /> <br /> kasan_report();<br /> print_report();<br /> print_address_description();<br /> kasan_find_vm_area();<br /> find_vm_area();<br /> spin_lock(&amp;vn-&gt;busy.lock) // deadlock!<br /> <br /> To prevent possible deadlock while kasan reports, remove kasan_find_vm_area().

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.18 (including) 6.1.146 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.99 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.39 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.15.7 (excluding)
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*