CVE-2025-38596
Last modified
CVE-2025-38596 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF in panthor_gem_create_with_handle() debugfs code The object is potentially already gone after the drm_gem_object_put(). In general the object should be fully constructed before calling drm_gem_handle_create(), except the debugfs tracking uses a separate lock and list and separate flag to denotate whether the object is actually initialized. Since I'm touching this all anyway simplify this by only adding the object to the debugfs when it's ready for that, which allows us to delete that separate flag. panthor_gem_debugfs_bo_rm() already checks whether we've actually been added to the list or this is some error path cleanup. v2: Fix build issues for !CONFIG_DEBUGFS (Adrián) v3: Add linebreak and remove outdated comment (Liviu). EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF in panthor_gem_create_with_handle() debugfs code The object is potentially already gone after the drm_gem_object_put(). In general the object should be fully constructed before calling drm_gem_handle_create(), except the debugfs tracking uses a separate lock and list and separate flag to denotate whether the object is actually initialized. Since I'm touching this all anyway simplify this by only adding the object to the debugfs when it's ready for that, which allows us to delete that separate flag. panthor_gem_debugfs_bo_rm() already checks whether we've actually been added to the list or this is some error path cleanup. v2: Fix build issues for !CONFIG_DEBUGFS (Adrián) v3: Add linebreak and remove outdated comment (Liviu)
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 6.16 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-38596?
How severe is CVE-2025-38596?
How do I fix CVE-2025-38596?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-38590In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38591In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38592In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-38593In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-38594In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-38595In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-38597In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38598In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-38599In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-3860The CarDealerPress plugin for WordPress is vulnerable to Sto…6.4
- CVE-2025-38600In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38601In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2025-38596?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
