CVE-2025-38633
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/08/2025
Last modified:
26/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
clk: spacemit: mark K1 pll1_d8 as critical<br />
<br />
The pll1_d8 clock is enabled by the boot loader, and is ultimately a<br />
parent for numerous clocks, including those used by APB and AXI buses.<br />
Guodong Xu discovered that this clock got disabled while responding to<br />
getting -EPROBE_DEFER when requesting a reset controller.<br />
<br />
The needed clock (CLK_DMA, along with its parents) had already been<br />
enabled. To respond to the probe deferral return, the CLK_DMA clock<br />
was disabled, and this led to parent clocks also reducing their enable<br />
count. When the enable count for pll1_d8 was decremented it became 0,<br />
which caused it to be disabled. This led to a system hang.<br />
<br />
Marking that clock critical resolves this by preventing it from being<br />
disabled.<br />
<br />
Define a new macro CCU_FACTOR_GATE_DEFINE() to allow clock flags to<br />
be supplied for a CCU_FACTOR_GATE clock.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:6.16:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



