CVE-2025-38696 Details
Description
In the Linux kernel, the following vulnerability has been resolved: MIPS: Don't crash in stack_top() for tasks without ABI or vDSO Not all tasks have an ABI associated or vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will derefence the NULL ABI pointer and crash. This can for example happen when using kunit: mips_stack_top+0x28/0xc0 arch_pick_mmap_layout+0x190/0x220 kunit_vm_mmap_init+0xf8/0x138 __kunit_add_resource+0x40/0xa8 kunit_vm_mmap+0x88/0xd8 usercopy_test_init+0xb8/0x240 kunit_try_run_case+0x5c/0x1a8 kunit_generic_run_threadfn_adapter+0x28/0x50 kthread+0x118/0x240 ret_from_kernel_thread+0x14/0x1c Only dereference the ABI point if it is set. The GIC page is also included as it is specific to the vDSO. Also move the randomization adjustment into the same conditional.
A denial-of-service vulnerability has been identified in the Linux kernel's MIPS architecture handling. The issue arises in the 'stack_top()' function, where tasks without an associated ABI or vDSO, such as kernel threads, can cause a crash by dereferencing a NULL pointer. This vulnerability can be triggered during the execution of certain KUnit tests, leading to a system crash.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-032379.html | siemens-SADP | |
| https://git.kernel.org/stable/c/24d098b6f69b0aa806ffcb3e18259bee31650b28 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5b6839b572b503609b9b58bc6c04a816eefa0794 | kernel.org | Patch |
| https://git.kernel.org/stable/c/82d140f6aab5e89a9d3972697a0dbe1498752d9b | kernel.org | Patch |
| https://git.kernel.org/stable/c/ab18e48a503230d675e824a0d68a108bdff42503 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bd90dbd196831f5c2620736dc221db2634cf1e8e | kernel.org | Patch |
| https://git.kernel.org/stable/c/cddf47d20b0325dc8a4e57b833fe96e8f36c42a4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e78033e59444d257d095b73ce5d20625294f6ec2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e9f4a6b3421e936c3ee9d74710243897d74dbaa2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f22de2027b206ddfb8a075800bb5d0dacf2da4b8 | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html | CVE | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.14.77, < 4.15 >= 4.18.15, < 4.19 >= 4.19.1, < 5.4.297 >= 5.5, < 5.10.241 >= 5.11, < 5.15.190 >= 5.16, < 6.1.149 >= 6.2, < 6.6.103 >= 6.7, < 6.12.43 >= 6.13, < 6.15.11 >= 6.16, < 6.16.2 4.19 - 4.19 rc8 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Jan 9, 2026 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Sep 4, 2025 | New CVE Received | kernel.org |