Skip to main content

Threats Tagged 'cve-2025-38500'

View all threats tagged with 'cve-2025-38500'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-38500

Threats Tagged 'cve-2025-38500'

Click on any threat for detailed analysis and mitigation recommendations

0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too (CVE-2025-37823) * kernel: i40e: fix MMIO write access to an invalid page in i40e_clear_hw (CVE-2025-38200) * kernel: drm/gem: Acquire references on GEM handles for framebuffers (CVE-2025-38449) * kernel: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry (CVE-2025-38472) * kernel: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (CVE-2025-38500) * kernel: smb: client: fix use-after-free in cifs_oplock_break (CVE-2025-38527) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Published: 2025-09-10 Updated: 2025-11-11 Reference: CVE-2025-38500 2025-11-11 Update: Added patch versions for Ubuntu node pools in GKE. 2025-10-16 Update: Added patch versions and a severity rating for GDC software for VMware. GKE Updated: 2025-11-11 Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-38500 GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Unconfined profile or allow CAP_NET_ADMIN . Clusters using GKE Sandbox aren't impacted. What should I do? 2025-11-11 Update: The following versions of GKE are updated with code to fix this vulnerability on Ubuntu. Upgrade your Ubuntu node pools to the following versions or later: 1.32.9-gke.1207000 1.33.5-gke.1308000 1.34.1-gke.2037000 The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later: 1.33.4-gke.1036000 1.32.8-gke.1026000 1.31.12-gke.1014000 1.30.14-gke.1108000 1.29.15-gke.1820000 1.28.15-gke.2599000 You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel . High GDC (VMware) Updated: 2025-10-16 Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-38500 What should I do? 2025-10-16 Update: The following versions of GDC software for VMware are updated with code to fix this vulnerability. Upgrade your GDC software for VMware clusters to the following versions or later: 1.31.1000-gke.44 Note: Patch versions and a severity assessment for GDC software for VMware are in progress. We'll update this bulletin with that information when it's available. High GKE on AWS Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-38500 What should I do? Note: Patch versions and a severity assessment for GKE on AWS are in progress. We'll update this bulletin with that information when it's available. Pending GKE on Azure Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-38500 What should I do? Note: Patch versions and a severity assessment for GKE on Azure are in progress. We'll update this bulletin with that information when it's available. Pending GDC (bare metal) Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-38500 What should I do? There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. None

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too Similarly to the previous patch, we need to safe guard hfsc_dequeue() too. But for this one, we don't have a reliable reproducer.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: ublk: make sure ubq->canceling is set when queue is frozen Now ublk driver depends on `ubq->canceling` for deciding if the request can be dispatched via uring_cmd & io_uring_cmd_complete_in_task(). Once ubq->canceling is set, the uring_cmd can be done via ublk_cancel_cmd() and io_uring_cmd_done(). So set ubq->canceling when queue is frozen, this way makes sure that the flag can be observed from ublk_queue_rq() reliably, and avoids use-after-free on uring_cmd.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-2025-38500
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses