Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-38696— MIPS: Don't crash in stack_top() for tasks without ABI or vDSO

AI Predicted 5.5 Difficulty: Theoretical EPSS 0.17% · P7

Possible ATT&CK Techniques 1AI

T1583.001 · Domains

Affected Version Matrix 24

VendorProductVersion RangeStatus
LinuxLinuxea7e0480a4b695d0aa6b3fa99bd658a003122113< ab18e48a503230d675e824a0d68a108bdff42503affected
ea7e0480a4b695d0aa6b3fa99bd658a003122113< e78033e59444d257d095b73ce5d20625294f6ec2affected
ea7e0480a4b695d0aa6b3fa99bd658a003122113< bd90dbd196831f5c2620736dc221db2634cf1e8eaffected
ea7e0480a4b695d0aa6b3fa99bd658a003122113< 5b6839b572b503609b9b58bc6c04a816eefa0794affected
ea7e0480a4b695d0aa6b3fa99bd658a003122113< f22de2027b206ddfb8a075800bb5d0dacf2da4b8affected
ea7e0480a4b695d0aa6b3fa99bd658a003122113< 82d140f6aab5e89a9d3972697a0dbe1498752d9baffected
ea7e0480a4b695d0aa6b3fa99bd658a003122113< 24d098b6f69b0aa806ffcb3e18259bee31650b28affected
ea7e0480a4b695d0aa6b3fa99bd658a003122113< cddf47d20b0325dc8a4e57b833fe96e8f36c42a4affected
… +16 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-38696

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MIPS: Don't crash in stack_top() for tasks without ABI or vDSO
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: MIPS: Don't crash in stack_top() for tasks without ABI or vDSO Not all tasks have an ABI associated or vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will derefence the NULL ABI pointer and crash. This can for example happen when using kunit: mips_stack_top+0x28/0xc0 arch_pick_mmap_layout+0x190/0x220 kunit_vm_mmap_init+0xf8/0x138 __kunit_add_resource+0x40/0xa8 kunit_vm_mmap+0x88/0xd8 usercopy_test_init+0xb8/0x240 kunit_try_run_case+0x5c/0x1a8 kunit_generic_run_threadfn_adapter+0x28/0x50 kthread+0x118/0x240 ret_from_kernel_thread+0x14/0x1c Only dereference the ABI point if it is set. The GIC page is also included as it is specific to the vDSO. Also move the randomization adjustment into the same conditional.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于stack_top函数未检查ABI空指针。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux ea7e0480a4b695d0aa6b3fa99bd658a003122113 ~ ab18e48a503230d675e824a0d68a108bdff42503 -
LinuxLinux 4.19 -

II. Public POCs for CVE-2025-38696

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38696

登录查看更多情报信息。

Patches & Fixes for CVE-2025-38696 (1)

Same Patch Batch · Linux · 2025-09-04 · 52 CVEs total

CVE-2025-387089.8 CRITICALdrbd: add missing kref_get in handle_write_conflicts
CVE-2025-387249.8 CRITICALnfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
CVE-2025-387289.1 CRITICALsmb3: fix for slab out of bounds on mount to ksmbd
CVE-2025-386888.8 HIGHiommufd: Prevent ALIGN() overflow
CVE-2025-386977.8 HIGHjfs: upper bound check of tree index in dbAllocAG
CVE-2025-387227.8 HIGHhabanalabs: fix UAF in export_dmabuf()
CVE-2025-386857.8 HIGHfbdev: Fix vmalloc out-of-bounds write in fast_imageblit
CVE-2025-387187.8 HIGHsctp: linearize cloned gso packets in sctp_rcv
CVE-2025-387177.8 HIGHnet: kcm: Fix race condition in kcm_unattach()
CVE-2025-387157.8 HIGHhfs: fix slab-out-of-bounds in hfs_bnode_read()
CVE-2025-387107.8 HIGHgfs2: Validate i_depth for exhash directories
CVE-2025-387307.8 HIGHio_uring/net: commit partial buffers on retry
CVE-2025-387037.8 HIGHdrm/xe: Make dma-fences compliant with the safe access rules
CVE-2025-387147.8 HIGHhfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
CVE-2025-386797.3 HIGHmedia: venus: Fix OOB read due to missing payload bound check
CVE-2025-386877.3 HIGHcomedi: fix race between polling and detaching
CVE-2025-387137.1 HIGHhfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
CVE-2025-387077.1 HIGHfs/ntfs3: Add sanity check for file name
CVE-2025-38680media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
CVE-2025-38693media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_t

Showing top 20 of 52 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38696

No comments yet


Leave a comment