CVE Database
/

CVE-2025-38469

Back to search

CVE-2025-38469

Published: Jul 28, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host for more than one event channel potr (nr_ports > 1). After the kmalloc_array(), the error paths need to go through the "out" label, but the call to kvm_read_guest_virt() does not. [Adjusted commit message. - Paolo]

VendorProductVersions

Linux

Linux

affected
92c58965e9656dc6e682a8ffe520fac0fb256d13 - < 3ee59c38ae7369ad1f7b846e05633ccf0d159fab
affected
92c58965e9656dc6e682a8ffe520fac0fb256d13 - < fd627ac8a5cff4d45269f164b13ddddc0726f2cc
affected
92c58965e9656dc6e682a8ffe520fac0fb256d13 - < 061c553c66bc1638c280739999224c8000fd4602
affected
92c58965e9656dc6e682a8ffe520fac0fb256d13 - < 5a53249d149f48b558368c5338b9921b76a12f8c

Linux

Linux

affected
6.2
unaffected
0 - < 6.2
unaffected
6.6.100 - <= 6.6.*
unaffected
6.12.40 - <= 6.12.*
unaffected
6.15.8 - <= 6.15.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now