CVE-2025-38586 Details
Description
In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix fp initialization for exception boundary In the ARM64 BPF JIT when prog->aux->exception_boundary is set for a BPF program, find_used_callee_regs() is not called because for a program acting as exception boundary, all callee saved registers are saved. find_used_callee_regs() sets `ctx->fp_used = true;` when it sees FP being used in any of the instructions. For programs acting as exception boundary, ctx->fp_used remains false even if frame pointer is used by the program and therefore, FP is not set-up for such programs in the prologue. This can cause the kernel to crash due to a pagefault. Fix it by setting ctx->fp_used = true for exception boundary programs as fp is always saved in such programs.
A vulnerability has been identified in the Linux kernel's BPF Just-In-Time (JIT) compiler for ARM64 architecture. When a BPF program is marked as an exception boundary, the JIT compiler fails to properly initialize the frame pointer (FP) in the program's prologue. This oversight occurs because the function responsible for tracking register usage does not recognize that the frame pointer is being used, leading to a situation where the kernel can crash due to a page fault. The issue arises in several versions of the Linux kernel.
The vulnerability has been addressed in the Linux kernel. Users should upgrade to the latest version where this issue has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0dbef493cae7d451f740558665893c000adb2321 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1ce30231e0a2c8c361ee5f8f7f265fc17130adce | kernel.org | Patch |
| https://git.kernel.org/stable/c/b114fcee766d5101eada1aca7bb5fd0a86c89b35 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e23184725dbb72d5d02940222eee36dbba2aa422 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.12, < 6.12.42 >= 6.13, < 6.15.10 >= 6.16, < 6.16.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 26, 2025 | Initial Analysis | [email protected] |
| Aug 19, 2025 | New CVE Received | kernel.org |