{"id":"DEBIAN-CVE-2025-38255","details":"In the Linux kernel, the following vulnerability has been resolved:  lib/group_cpus: fix NULL pointer dereference from group_cpus_evenly()  While testing null_blk with configfs, echo 0 \u003e poll_queues will trigger following panic:  BUG: kernel NULL pointer dereference, address: 0000000000000010 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 27 UID: 0 PID: 920 Comm: bash Not tainted 6.15.0-02023-gadbdb95c8696-dirty #1238 PREEMPT(undef) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014 RIP: 0010:__bitmap_or+0x48/0x70 Call Trace:  \u003cTASK\u003e  __group_cpus_evenly+0x822/0x8c0  group_cpus_evenly+0x2d9/0x490  blk_mq_map_queues+0x1e/0x110  null_map_queues+0xc9/0x170 [null_blk]  blk_mq_update_queue_map+0xdb/0x160  blk_mq_update_nr_hw_queues+0x22b/0x560  nullb_update_nr_hw_queues+0x71/0xf0 [null_blk]  nullb_device_poll_queues_store+0xa4/0x130 [null_blk]  configfs_write_iter+0x109/0x1d0  vfs_write+0x26e/0x6f0  ksys_write+0x79/0x180  __x64_sys_write+0x1d/0x30  x64_sys_call+0x45c4/0x45f0  do_syscall_64+0xa5/0x240  entry_SYSCALL_64_after_hwframe+0x76/0x7e  Root cause is that numgrps is set to 0, and ZERO_SIZE_PTR is returned from kcalloc(), and later ZERO_SIZE_PTR will be deferenced.  Fix the problem by checking numgrps first in group_cpus_evenly(), and return NULL directly if numgrps is zero.  [yukuai3@huawei.com: also fix the non-SMP version]","modified":"2026-08-27T23:05:29.594776974Z","published":"2025-07-09T11:15:27.767Z","upstream":["CVE-2025-38255"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38255"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38255.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38255.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}