CVE-2025-38449: drm/gem: Acquire references on GEM handles for framebuffers
Published Jul 25, 2025
·Updated
drm/gem: Acquire references on GEM handles for framebuffers
Affected Software
11 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.96.2-1
Microsoft cbl2 kernel 5.15.186.1-1
Linux Linux kernel<6.6.99
Linux Linux kernel>=6.7<6.12.39
Linux Linux kernel>=6.13<6.15.7
Linux Linux kernel=6.16-rc1
Linux Linux kernel=6.16-rc2
Linux Linux kernel=6.16-rc3
Linux Linux kernel=6.16-rc4
Microsoft azl3 kernel 6.6.96.2-2<6.6.104.2-1
6.6.104.2-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.104.2-1
Event History
Jul 25, 2025
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
DescriptionSeverity
Data Sourced
via Red Hat·04:03 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·11:02 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·11:02 PM
SeverityAffected Software
Sep 4, 2025
Updated
via Microsoft·06:02 AM
DescriptionSeverityWeakness
Updated
via Microsoft·06:02 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-38449?
CVE-2025-38449 has been classified with a severity level that indicates a risk to system stability.
2
What are the potential impacts of CVE-2025-38449?
CVE-2025-38449 could lead to system crashes and data corruption if exploited.
3
How do I fix CVE-2025-38449?
To mitigate CVE-2025-38449, ensure your Linux kernel is updated to the latest patched version.
4
What systems are affected by CVE-2025-38449?
CVE-2025-38449 affects various versions of the Linux kernel that utilize GEM handles for framebuffers.
5
Is there a workaround for CVE-2025-38449?
Currently, there are no known workarounds for CVE-2025-38449 other than applying the security update.