CVE-2025-38469
Published: Jul 28, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host for more than one event channel potr (nr_ports > 1). After the kmalloc_array(), the error paths need to go through the "out" label, but the call to kvm_read_guest_virt() does not. [Adjusted commit message. - Paolo]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 92c58965e9656dc6e682a8ffe520fac0fb256d13 - < 3ee59c38ae7369ad1f7b846e05633ccf0d159fabaffected 92c58965e9656dc6e682a8ffe520fac0fb256d13 - < fd627ac8a5cff4d45269f164b13ddddc0726f2ccaffected 92c58965e9656dc6e682a8ffe520fac0fb256d13 - < 061c553c66bc1638c280739999224c8000fd4602affected 92c58965e9656dc6e682a8ffe520fac0fb256d13 - < 5a53249d149f48b558368c5338b9921b76a12f8c |
Linux | Linux | affected 6.2unaffected 0 - < 6.2unaffected 6.6.100 - <= 6.6.*unaffected 6.12.40 - <= 6.12.*unaffected 6.15.8 - <= 6.15.*+1 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now