CVE-2025-38649: arm64: dts: qcom: qcs615: fix a crash issue caused by infinite loop for Coresight

Published Aug 22, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

arm64: dts: qcom: qcs615: fix a crash issue caused by infinite loop for Coresight

An infinite loop has been created by the Coresight devices. When only a source device is enabled, the coresightfindactivatedsysfssink function is recursively invoked in an attempt to locate an active sink device, ultimately leading to a stack overflow and system crash. Therefore, disable the replicator1 to break the infinite loop and prevent a potential stack overflow.

replicator1out -> funnelswaoin6 -> tmcetfswaoin -> tmcetfswaoout | | replicator1in replicatorswaoin | | replicator0out1 replicatorswaoout0 | | replicator0in funnelin1in3 | | tmcetfout <- tmcetfin <- funnelmergout <- funnelmergin1 <- funnelin1out

[call trace] dumpbacktrace+0x9c/0x128 showstack+0x20/0x38 dumpstacklvl+0x48/0x60 dumpstack+0x18/0x28 panic+0x340/0x3b0 nmipanic+0x94/0xa0 panicbadstack+0x114/0x138 handlebadstack+0x34/0xb8 badstack+0x78/0x80 coresightfindactivatedsysfssink+0x28/0xa0 [coresight] coresightfindactivatedsysfssink+0x5c/0xa0 [coresight] coresightfindactivatedsysfssink+0x5c/0xa0 [coresight] coresightfindactivatedsysfssink+0x5c/0xa0 [coresight] coresightfindactivatedsysfssink+0x5c/0xa0 [coresight] ... coresightfindactivatedsysfssink+0x5c/0xa0 [coresight] coresightenablesysfs+0x80/0x2a0 [coresight]

side effect after the change: Only trace data originating from AOSS can reach the ETFSWAO and EUD sinks.

Affected Software

3 affected components
Linux Kernel
Linux Linux kernel>=6.14<6.15.10
Linux Linux kernel>=6.16<6.16.1

Event History

Aug 22, 2025
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-38649?

CVE-2025-38649 is classified as a vulnerability that can cause a denial of service due to an infinite loop in the Linux kernel's Coresight device.

2

How do I fix CVE-2025-38649?

To fix CVE-2025-38649, update the Linux kernel to the latest version where this vulnerability has been addressed.

3

What affected devices does CVE-2025-38649 target?

CVE-2025-38649 affects devices using the arm64 architecture in the Linux kernel that implement Coresight.

4

What are the implications of CVE-2025-38649?

The implications of CVE-2025-38649 include potential system crashes and unresponsiveness due to the infinite loop created by Coresight.

5

When was CVE-2025-38649 resolved?

CVE-2025-38649 was resolved in a kernel update that addressed the infinite loop issue with Coresight devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203