CVE-2025-38689

Source
https://cve.org/CVERecord?id=CVE-2025-38689
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38689.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-38689
Downstream
Published
2025-09-04T15:32:43Z
Modified
2026-08-12T03:51:38Z
Summary
x86/fpu: Fix NULL dereference in avx512_status()
Details

In the Linux kernel, the following vulnerability has been resolved:

x86/fpu: Fix NULL dereference in avx512_status()

Problem

With CONFIG_X86_DEBUG_FPU enabled, reading /proc/[kthread]/arch_status causes a warning and a NULL pointer dereference.

This is because the AVX-512 timestamp code uses x86_task_fpu() but doesn't check it for NULL. CONFIG_X86_DEBUG_FPU addles that function for kernel threads (PF_KTHREAD specifically), making it return NULL.

The point of the warning was to ensure that kernel threads only access task->fpu after going through kernel_fpu_begin()/_end(). Note: all kernel tasks exposed in /proc have a valid task->fpu.

Solution

One option is to silence the warning and check for NULL from x86_task_fpu(). However, that warning is fairly fresh and seems like a defense against misuse of the FPU state in kernel threads.

Instead, stop outputting AVX-512_elapsed_ms for kernel threads altogether. The data was garbage anyway because avx512_timestamp is only updated for user threads, not kernel threads.

If anyone ever wants to track kernel thread AVX-512 use, they can come back later and do it properly, separate from this bug fix.

[ dhansen: mostly rewrite changelog ]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38689.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
22aafe3bcb67472effdea1ccf0df20280192bbaf
Fixed
2ca887e81095b99d890a8878841f36f4920181e6
Fixed
31cd31c9e17ece125aad27259501a2af69ccb020

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38689.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.16.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38689.json"