-

CVE-2025-38469

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls

kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host
for more than one event channel potr (nr_ports > 1).

After the kmalloc_array(), the error paths need to go through the
"out" label, but the call to kvm_read_guest_virt() does not.

[Adjusted commit message. - Paolo]

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 3ee59c38ae7369ad1f7b846e05633ccf0d159fab
Version 92c58965e9656dc6e682a8ffe520fac0fb256d13
Status affected
Version < fd627ac8a5cff4d45269f164b13ddddc0726f2cc
Version 92c58965e9656dc6e682a8ffe520fac0fb256d13
Status affected
Version < 061c553c66bc1638c280739999224c8000fd4602
Version 92c58965e9656dc6e682a8ffe520fac0fb256d13
Status affected
Version < 5a53249d149f48b558368c5338b9921b76a12f8c
Version 92c58965e9656dc6e682a8ffe520fac0fb256d13
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.2
Status affected
Version < 6.2
Version 0
Status unaffected
Version <= 6.6.*
Version 6.6.100
Status unaffected
Version <= 6.12.*
Version 6.12.40
Status unaffected
Version <= 6.15.*
Version 6.15.8
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.059
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String