x86/resctrl Vulnerability in Linux Kernel Affects Multiple Platforms
CVE-2025-38049

5.5MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 April 2025

What is CVE-2025-38049?

A logic error in the Linux kernel's x86/resctrl functionality allows for a NULL pointer dereference when creating new control groups on platforms lacking cache occupancy monitors. The issue stems from the absence of allocated arrays in certain conditions, leading to potential operational disruptions. This vulnerability particularly affects systems relying on a cleanest CLOSID allocation based on dirty cache line counts, which is unnecessary for platforms without monitoring capabilities. A fix has been implemented to improve robustness and prevent similar issues.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 6eac36bb9eb0349c983313c71692c19d50b56878

Linux 6eac36bb9eb0349c983313c71692c19d50b56878

Linux 6eac36bb9eb0349c983313c71692c19d50b56878 < 93a418fc61da13d1ee4047d4d1327990f7a2816a

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.