CVE-2025-38520: drm/amdkfd: Don't call mmput from MMU notifier callback
Published Aug 16, 2025
·Updated
drm/amdkfd: Don't call mmput from MMU notifier callback
Affected Software
22 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=5.15.49<5.16
Linux Linux kernel>=5.18.6<5.19
Linux Linux kernel>=5.19.1<6.1.148
Linux Linux kernel>=6.2<6.6.101
Linux Linux kernel>=6.7<6.12.39
Linux Linux kernel>=6.13<6.15.7
Linux Linux kernel=5.19
Linux Linux kernel=5.19-rc2
Linux Linux kernel=5.19-rc3
Linux Linux kernel=5.19-rc4
Linux Linux kernel=5.19-rc5
Linux Linux kernel=5.19-rc6
Linux Linux kernel=5.19-rc7
Linux Linux kernel=5.19-rc8
Linux Linux kernel=6.16-rc1
Linux Linux kernel=6.16-rc2
Linux Linux kernel=6.16-rc3
Linux Linux kernel=6.16-rc4
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.96.2-1
Microsoft azl3 kernel 6.6.96.2-2<6.6.104.2-1
6.6.104.2-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.104.2-1
Event History
Aug 16, 2025
CVE Published
via MITRE·10:55 AM
Data Sourced
via MITRE·10:55 AM
Description
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·02:14 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·09:14 AM
DescriptionWeakness
Updated
via Microsoft·09:14 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-38520?
CVE-2025-38520 is categorized as a moderate severity vulnerability in the Linux kernel.
2
How do I fix CVE-2025-38520?
To fix CVE-2025-38520, update your Linux kernel to the latest patched version that addresses this vulnerability.
3
What types of systems are affected by CVE-2025-38520?
CVE-2025-38520 affects systems running vulnerable versions of the Linux kernel.
4
What specific component of the Linux kernel is impacted by CVE-2025-38520?
CVE-2025-38520 impacts the DRM subsystem, specifically within the amdkfd driver.
5
What are the potential consequences of CVE-2025-38520 if exploited?
Exploitation of CVE-2025-38520 could lead to a denial of service through improper memory management during process exiting.