CVE-2025-38131: coresight: prevent deactivate active config while enabling the config
Published Jul 3, 2025
·Updated
coresight: prevent deactivate active config while enabling the config
Affected Software
8 affected componentsFixes available
Linux Foundation Linux Kernel
Linux Linux kernel>=5.15<6.1.142
Linux Linux kernel>=6.2<6.6.94
Linux Linux kernel>=6.7<6.12.34
Linux Linux kernel>=6.13<6.15.3
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.92.2-2
Microsoft cbl2 kernel 5.15.186.1-1
Remediation
Event History
Jul 3, 2025
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
Description
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 7, 2025
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-38131?
CVE-2025-38131 has a medium severity rating as it relates to the configuration settings of the Linux kernel.
2
How do I fix CVE-2025-38131?
To fix CVE-2025-38131, ensure that you update to the latest stable version of the Linux kernel that includes the applied patches.
3
Which systems are affected by CVE-2025-38131?
CVE-2025-38131 affects the Linux kernel in systems utilizing the coresight configuration interface.
4
What are the risks associated with CVE-2025-38131?
The risks of CVE-2025-38131 include potential unexpected behavior if active configurations are deactivated while in use.
5
Is there a workaround for CVE-2025-38131?
Currently, the recommended action for CVE-2025-38131 is to apply the appropriate updates rather than relying on a workaround.