目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-38049— Linux kernel 安全漏洞

AI 预测 4.7 利用难度: 较易 EPSS 0.25% · P16

影响版本矩阵 10

厂商产品版本范围状态
LinuxLinux6eac36bb9eb0349c983313c71692c19d50b56878< a8a1bcc27d4607227088d80483164289b5348293affected
6eac36bb9eb0349c983313c71692c19d50b56878< ed5addb55e403ad6598102bcf546e068ae01fef6affected
6eac36bb9eb0349c983313c71692c19d50b56878< 93a418fc61da13d1ee4047d4d1327990f7a2816aaffected
6eac36bb9eb0349c983313c71692c19d50b56878< a121798ae669351ec0697c94f71c3a692b2a755baffected
6.9affected
< 6.9unaffected
6.12.23≤ 6.12.*unaffected
6.13.11≤ 6.13.*unaffected
… +2 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-38049 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors Commit 6eac36bb9eb0 ("x86/resctrl: Allocate the cleanest CLOSID by searching closid_num_dirty_rmid") added logic that causes resctrl to search for the CLOSID with the fewest dirty cache lines when creating a new control group, if requested by the arch code. This depends on the values read from the llc_occupancy counters. The logic is applicable to architectures where the CLOSID effectively forms part of the monitoring identifier and so do not allow complete freedom to choose an unused monitoring identifier for a given CLOSID. This support missed that some platforms may not have these counters. This causes a NULL pointer dereference when creating a new control group as the array was not allocated by dom_data_init(). As this feature isn't necessary on platforms that don't have cache occupancy monitors, add this to the check that occurs when a new control group is allocated.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未正确处理无监控器平台的CLOSID分配,可能导致空指针取消引用。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 6eac36bb9eb0349c983313c71692c19d50b56878 ~ a8a1bcc27d4607227088d80483164289b5348293 -
LinuxLinux 6.9 -

二、漏洞 CVE-2025-38049 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-38049 的情报信息

登录查看更多情报信息。

CVE-2025-38049 其他参考 (4)

同批安全公告 · Linux · 2025-04-18 · 共 23 条

CVE-2025-38637Linux kernel 安全漏洞
CVE-2025-37785Linux kernel 安全漏洞
CVE-2025-37860Linux kernel 安全漏洞
CVE-2025-37925Linux kernel 安全漏洞
CVE-2025-37893Linux kernel 安全漏洞
CVE-2025-38104Linux kernel 安全漏洞
CVE-2025-38152Linux kernel 安全漏洞
CVE-2025-38240Linux kernel 安全漏洞
CVE-2025-38479Linux kernel 安全漏洞
CVE-2025-38575Linux kernel 安全漏洞
CVE-2025-39688Linux kernel 安全漏洞
CVE-2025-37838Linux kernel 安全漏洞
CVE-2025-39735Linux kernel 安全漏洞
CVE-2025-39728Linux kernel 安全漏洞
CVE-2025-39755Linux kernel 安全漏洞
CVE-2025-39778Linux kernel 安全漏洞
CVE-2025-39930Linux kernel 安全漏洞
CVE-2025-39989Linux kernel 安全漏洞
CVE-2025-40014Linux kernel 安全漏洞
CVE-2025-40114Linux kernel 安全漏洞

显示前 20 条,共 23 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38049

暂无评论


发表评论