CVE-2025-38309

Source
https://cve.org/CVERecord?id=CVE-2025-38309
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38309.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-38309
Downstream
Published
2025-07-10T07:42:18.701Z
Modified
2026-04-02T12:47:55.398482Z
Summary
drm/xe/vm: move xe_svm_init() earlier
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/vm: move xesvminit() earlier

In xevmcloseandput() we need to be able to call xesvmfini(), however during vm creation we can call this on the error path, before having actually initialised the svm state, leading to various splats followed by a fatal NPD.

(cherry picked from commit 4f296d77cf49fcb5f90b4674123ad7f3a0676165)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38309.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6fd979c2f33150e8261d87d2946f94f66f22ddaa
Fixed
f5e6a6a8aa46d44ec7a240766cf3b7dd077718b9
Fixed
8cf8cde41ad01150afbd1327ad1942387787f7fd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38309.json"