Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-38263— bcache: fix NULL pointer in cache_set_flush()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于bcache缓存集分配错误,可能导致内存分配失败。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.15% · P5

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux cafe563591446cf80bfbc2fe3bc72a2e36cf1060< d54681938b777488e5dfb781b566d16adad991de affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 1f25f2d3fa29325320c19a30abf787e0bd5fc91b affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< c4f5e7e417034b05f5d2f5fa9a872db897da69bd affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 553f560e0a74a7008ad9dba05c3fd05da296befb affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 667c3f52373ff5354cb3543e27237eb7df7b2333 affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 3f9e128186c99a117e304f1dce6d0b9e50c63cd8 affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 1e46ed947ec658f89f1a910d880cd05e42d3763e affected
3.10 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-38263

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bcache: fix NULL pointer in cache_set_flush()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bcache: fix NULL pointer in cache_set_flush() 1. LINE#1794 - LINE#1887 is some codes about function of bch_cache_set_alloc(). 2. LINE#2078 - LINE#2142 is some codes about function of register_cache_set(). 3. register_cache_set() will call bch_cache_set_alloc() in LINE#2098. 1794 struct cache_set *bch_cache_set_alloc(struct cache_sb *sb) 1795 { ... 1860 if (!(c->devices = kcalloc(c->nr_uuids, sizeof(void *), GFP_KERNEL)) || 1861 mempool_init_slab_pool(&c->search, 32, bch_search_cache) || 1862 mempool_init_kmalloc_pool(&c->bio_meta, 2, 1863 sizeof(struct bbio) + sizeof(struct bio_vec) * 1864 bucket_pages(c)) || 1865 mempool_init_kmalloc_pool(&c->fill_iter, 1, iter_size) || 1866 bioset_init(&c->bio_split, 4, offsetof(struct bbio, bio), 1867 BIOSET_NEED_BVECS|BIOSET_NEED_RESCUER) || 1868 !(c->uuids = alloc_bucket_pages(GFP_KERNEL, c)) || 1869 !(c->moving_gc_wq = alloc_workqueue("bcache_gc", 1870 WQ_MEM_RECLAIM, 0)) || 1871 bch_journal_alloc(c) || 1872 bch_btree_cache_alloc(c) || 1873 bch_open_buckets_alloc(c) || 1874 bch_bset_sort_state_init(&c->sort, ilog2(c->btree_pages))) 1875 goto err; ^^^^^^^^ 1876 ... 1883 return c; 1884 err: 1885 bch_cache_set_unregister(c); ^^^^^^^^^^^^^^^^^^^^^^^^^^^ 1886 return NULL; 1887 } ... 2078 static const char *register_cache_set(struct cache *ca) 2079 { ... 2098 c = bch_cache_set_alloc(&ca->sb); 2099 if (!c) 2100 return err; ^^^^^^^^^^ ... 2128 ca->set = c; 2129 ca->set->cache[ca->sb.nr_this_dev] = ca; ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ... 2138 return NULL; 2139 err: 2140 bch_cache_set_unregister(c); 2141 return err; 2142 } (1) If LINE#1860 - LINE#1874 is true, then do 'goto err'(LINE#1875) and call bch_cache_set_unregister()(LINE#1885). (2) As (1) return NULL(LINE#1886), LINE#2098 - LINE#2100 would return. (3) As (2) has returned, LINE#2128 - LINE#2129 would do *not* give the value to c->cache[], it means that c->cache[] is NULL. LINE#1624 - LINE#1665 is some codes about function of cache_set_flush(). As (1), in LINE#1885 call bch_cache_set_unregister() ---> bch_cache_set_stop() ---> closure_queue() -.-> cache_set_flush() (as below LINE#1624) 1624 static void cache_set_flush(struct closure *cl) 1625 { ... 1654 for_each_cache(ca, c, i) 1655 if (ca->alloc_thread) ^^ 1656 kthread_stop(ca->alloc_thread); ... 1665 } (4) In LINE#1655 ca is NULL(see (3)) in cache_set_flush() then the kernel crash occurred as below: [ 846.712887] bcache: register_cache() error drbd6: cannot allocate memory [ 846.713242] bcache: register_bcache() error : failed to register device [ 846.713336] bcache: cache_set_free() Cache set 2f84bdc1-498a-4f2f-98a7-01946bf54287 unregistered [ 846.713768] BUG: unable to handle kernel NULL pointer dereference at 00000000000009f8 [ 846.714790] PGD 0 P4D 0 [ 846.715129] Oops: 0000 [#1] SMP PTI [ 846.715472] CPU: 19 PID: 5057 Comm: kworker/19:16 Kdump: loaded Tainted: G OE --------- - - 4.18.0-147.5.1.el8_1.5es.3.x86_64 #1 [ 846.716082] Hardware name: ESPAN GI-25212/X11DPL-i, BIOS 2.1 06/15/2018 [ 846.716451] Workqueue: events cache_set_flush [bcache] [ 846.716808] RIP: 0010:cache_set_flush+0xc9/0x1b0 [bcache] [ 846.717155] Code: 00 4c 89 a5 b0 03 00 00 48 8b 85 68 f6 ff ff a8 08 0f 84 88 00 00 00 31 db 66 83 bd 3c f7 ff ff 00 48 8b 85 48 ff ff ff 74 28 <48> 8b b8 f8 09 00 0 ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于bcache缓存集分配错误,可能导致内存分配失败。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux cafe563591446cf80bfbc2fe3bc72a2e36cf1060 ~ d54681938b777488e5dfb781b566d16adad991de -
Linux Linux 3.10 -

II. Public POCs for CVE-2025-38263

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38263

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-07-09 · 26 CVEs total

CVE-2025-38264 9.8 CRITICAL nvme-tcp: sanitize request list handling
CVE-2025-38246 9.8 CRITICAL bnxt: properly flush XDP redirect lists
CVE-2025-38253 8.8 HIGH HID: wacom: fix crash in wacom_aes_battery_handler()
CVE-2025-38238 8.8 HIGH scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out
CVE-2025-38252 7.8 HIGH cxl/ras: Fix CPER handler device confusion
CVE-2025-38261 7.8 HIGH riscv: save the SR_SUM status over switches
CVE-2025-38262 7.8 HIGH tty: serial: uartlite: register uart driver in init
CVE-2025-38250 7.8 HIGH Bluetooth: hci_core: Fix use-after-free in vhci_flush()
CVE-2025-38242 7.8 HIGH mm: userfaultfd: fix race of userfaultfd_move and swap cache
CVE-2025-38248 7.8 HIGH bridge: mcast: Fix use-after-free during router port configuration
CVE-2025-38244 7.5 HIGH smb: client: fix potential deadlock when reconnecting channels
CVE-2025-38239 7.3 HIGH scsi: megaraid_sas: Fix invalid node index
CVE-2025-38257 7.3 HIGH s390/pkey: Prevent overflow in size calculation for memdup_user()
CVE-2025-38255 lib/group_cpus: fix NULL pointer dereference from group_cpus_evenly()
CVE-2025-38241 mm/shmem, swap: fix softlockup with mTHP swapin
CVE-2025-38260 btrfs: handle csum tree error with rescue=ibadroots correctly
CVE-2025-38259 ASoC: codecs: wcd9335: Fix missing free of regulator supplies
CVE-2025-38258 mm/damon/sysfs-schemes: free old damon_sysfs_scheme_filter->memcg_path on write
CVE-2025-38256 io_uring/rsrc: fix folio unpinning
CVE-2025-38254 drm/amd/display: Add sanity checks for drm_edid_raw()

Showing top 20 of 26 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38263

No comments yet


Leave a comment