Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-38263— bcache: fix NULL pointer in cache_set_flush()

AI Predicted 7.8 Difficulty: Moderate EPSS 0.15% · P5

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinuxcafe563591446cf80bfbc2fe3bc72a2e36cf1060< d54681938b777488e5dfb781b566d16adad991deaffected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 1f25f2d3fa29325320c19a30abf787e0bd5fc91baffected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< c4f5e7e417034b05f5d2f5fa9a872db897da69bdaffected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 553f560e0a74a7008ad9dba05c3fd05da296befbaffected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 667c3f52373ff5354cb3543e27237eb7df7b2333affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 3f9e128186c99a117e304f1dce6d0b9e50c63cd8affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 1e46ed947ec658f89f1a910d880cd05e42d3763eaffected
3.10affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-38263

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bcache: fix NULL pointer in cache_set_flush()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bcache: fix NULL pointer in cache_set_flush() 1. LINE#1794 - LINE#1887 is some codes about function of bch_cache_set_alloc(). 2. LINE#2078 - LINE#2142 is some codes about function of register_cache_set(). 3. register_cache_set() will call bch_cache_set_alloc() in LINE#2098. 1794 struct cache_set *bch_cache_set_alloc(struct cache_sb *sb) 1795 { ... 1860 if (!(c->devices = kcalloc(c->nr_uuids, sizeof(void *), GFP_KERNEL)) || 1861 mempool_init_slab_pool(&c->search, 32, bch_search_cache) || 1862 mempool_init_kmalloc_pool(&c->bio_meta, 2, 1863 sizeof(struct bbio) + sizeof(struct bio_vec) * 1864 bucket_pages(c)) || 1865 mempool_init_kmalloc_pool(&c->fill_iter, 1, iter_size) || 1866 bioset_init(&c->bio_split, 4, offsetof(struct bbio, bio), 1867 BIOSET_NEED_BVECS|BIOSET_NEED_RESCUER) || 1868 !(c->uuids = alloc_bucket_pages(GFP_KERNEL, c)) || 1869 !(c->moving_gc_wq = alloc_workqueue("bcache_gc", 1870 WQ_MEM_RECLAIM, 0)) || 1871 bch_journal_alloc(c) || 1872 bch_btree_cache_alloc(c) || 1873 bch_open_buckets_alloc(c) || 1874 bch_bset_sort_state_init(&c->sort, ilog2(c->btree_pages))) 1875 goto err; ^^^^^^^^ 1876 ... 1883 return c; 1884 err: 1885 bch_cache_set_unregister(c); ^^^^^^^^^^^^^^^^^^^^^^^^^^^ 1886 return NULL; 1887 } ... 2078 static const char *register_cache_set(struct cache *ca) 2079 { ... 2098 c = bch_cache_set_alloc(&ca->sb); 2099 if (!c) 2100 return err; ^^^^^^^^^^ ... 2128 ca->set = c; 2129 ca->set->cache[ca->sb.nr_this_dev] = ca; ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ... 2138 return NULL; 2139 err: 2140 bch_cache_set_unregister(c); 2141 return err; 2142 } (1) If LINE#1860 - LINE#1874 is true, then do 'goto err'(LINE#1875) and call bch_cache_set_unregister()(LINE#1885). (2) As (1) return NULL(LINE#1886), LINE#2098 - LINE#2100 would return. (3) As (2) has returned, LINE#2128 - LINE#2129 would do *not* give the value to c->cache[], it means that c->cache[] is NULL. LINE#1624 - LINE#1665 is some codes about function of cache_set_flush(). As (1), in LINE#1885 call bch_cache_set_unregister() ---> bch_cache_set_stop() ---> closure_queue() -.-> cache_set_flush() (as below LINE#1624) 1624 static void cache_set_flush(struct closure *cl) 1625 { ... 1654 for_each_cache(ca, c, i) 1655 if (ca->alloc_thread) ^^ 1656 kthread_stop(ca->alloc_thread); ... 1665 } (4) In LINE#1655 ca is NULL(see (3)) in cache_set_flush() then the kernel crash occurred as below: [ 846.712887] bcache: register_cache() error drbd6: cannot allocate memory [ 846.713242] bcache: register_bcache() error : failed to register device [ 846.713336] bcache: cache_set_free() Cache set 2f84bdc1-498a-4f2f-98a7-01946bf54287 unregistered [ 846.713768] BUG: unable to handle kernel NULL pointer dereference at 00000000000009f8 [ 846.714790] PGD 0 P4D 0 [ 846.715129] Oops: 0000 [#1] SMP PTI [ 846.715472] CPU: 19 PID: 5057 Comm: kworker/19:16 Kdump: loaded Tainted: G OE --------- - - 4.18.0-147.5.1.el8_1.5es.3.x86_64 #1 [ 846.716082] Hardware name: ESPAN GI-25212/X11DPL-i, BIOS 2.1 06/15/2018 [ 846.716451] Workqueue: events cache_set_flush [bcache] [ 846.716808] RIP: 0010:cache_set_flush+0xc9/0x1b0 [bcache] [ 846.717155] Code: 00 4c 89 a5 b0 03 00 00 48 8b 85 68 f6 ff ff a8 08 0f 84 88 00 00 00 31 db 66 83 bd 3c f7 ff ff 00 48 8b 85 48 ff ff ff 74 28 <48> 8b b8 f8 09 00 0 ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于bcache缓存集分配错误,可能导致内存分配失败。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux cafe563591446cf80bfbc2fe3bc72a2e36cf1060 ~ d54681938b777488e5dfb781b566d16adad991de -
LinuxLinux 3.10 -

II. Public POCs for CVE-2025-38263

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38263

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-07-09 · 26 CVEs total

CVE-2025-382649.8 CRITICALnvme-tcp: sanitize request list handling
CVE-2025-382469.8 CRITICALbnxt: properly flush XDP redirect lists
CVE-2025-382538.8 HIGHHID: wacom: fix crash in wacom_aes_battery_handler()
CVE-2025-382388.8 HIGHscsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out
CVE-2025-382527.8 HIGHcxl/ras: Fix CPER handler device confusion
CVE-2025-382617.8 HIGHriscv: save the SR_SUM status over switches
CVE-2025-382627.8 HIGHtty: serial: uartlite: register uart driver in init
CVE-2025-382507.8 HIGHBluetooth: hci_core: Fix use-after-free in vhci_flush()
CVE-2025-382427.8 HIGHmm: userfaultfd: fix race of userfaultfd_move and swap cache
CVE-2025-382487.8 HIGHbridge: mcast: Fix use-after-free during router port configuration
CVE-2025-382447.5 HIGHsmb: client: fix potential deadlock when reconnecting channels
CVE-2025-382397.3 HIGHscsi: megaraid_sas: Fix invalid node index
CVE-2025-382577.3 HIGHs390/pkey: Prevent overflow in size calculation for memdup_user()
CVE-2025-38255lib/group_cpus: fix NULL pointer dereference from group_cpus_evenly()
CVE-2025-38241mm/shmem, swap: fix softlockup with mTHP swapin
CVE-2025-38260btrfs: handle csum tree error with rescue=ibadroots correctly
CVE-2025-38259ASoC: codecs: wcd9335: Fix missing free of regulator supplies
CVE-2025-38258mm/damon/sysfs-schemes: free old damon_sysfs_scheme_filter->memcg_path on write
CVE-2025-38256io_uring/rsrc: fix folio unpinning
CVE-2025-38254drm/amd/display: Add sanity checks for drm_edid_raw()

Showing top 20 of 26 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38263

No comments yet


Leave a comment