{"id":"DEBIAN-CVE-2025-38263","details":"In the Linux kernel, the following vulnerability has been resolved:  bcache: fix NULL pointer in cache_set_flush()  1. LINE#1794 - LINE#1887 is some codes about function of    bch_cache_set_alloc(). 2. LINE#2078 - LINE#2142 is some codes about function of    register_cache_set(). 3. register_cache_set() will call bch_cache_set_alloc() in LINE#2098.   1794 struct cache_set *bch_cache_set_alloc(struct cache_sb *sb)  1795 {  ...  1860         if (!(c-\u003edevices = kcalloc(c-\u003enr_uuids, sizeof(void *), GFP_KERNEL)) ||  1861             mempool_init_slab_pool(&c-\u003esearch, 32, bch_search_cache) ||  1862             mempool_init_kmalloc_pool(&c-\u003ebio_meta, 2,  1863                                 sizeof(struct bbio) + sizeof(struct bio_vec) *  1864                                 bucket_pages(c)) ||  1865             mempool_init_kmalloc_pool(&c-\u003efill_iter, 1, iter_size) ||  1866             bioset_init(&c-\u003ebio_split, 4, offsetof(struct bbio, bio),  1867                         BIOSET_NEED_BVECS|BIOSET_NEED_RESCUER) ||  1868             !(c-\u003euuids = alloc_bucket_pages(GFP_KERNEL, c)) ||  1869             !(c-\u003emoving_gc_wq = alloc_workqueue(\"bcache_gc\",  1870                                                 WQ_MEM_RECLAIM, 0)) ||  1871             bch_journal_alloc(c) ||  1872             bch_btree_cache_alloc(c) ||  1873             bch_open_buckets_alloc(c) ||  1874             bch_bset_sort_state_init(&c-\u003esort, ilog2(c-\u003ebtree_pages)))  1875                 goto err;                       ^^^^^^^^  1876  ...  1883         return c;  1884 err:  1885         bch_cache_set_unregister(c);               ^^^^^^^^^^^^^^^^^^^^^^^^^^^  1886         return NULL;  1887 }  ...  2078 static const char *register_cache_set(struct cache *ca)  2079 {  ...  2098         c = bch_cache_set_alloc(&ca-\u003esb);  2099         if (!c)  2100                 return err;                       ^^^^^^^^^^  ...  2128         ca-\u003eset = c;  2129         ca-\u003eset-\u003ecache[ca-\u003esb.nr_this_dev] = ca;               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^  ...  2138         return NULL;  2139 err:  2140         bch_cache_set_unregister(c);  2141         return err;  2142 }  (1) If LINE#1860 - LINE#1874 is true, then do 'goto err'(LINE#1875) and     call bch_cache_set_unregister()(LINE#1885). (2) As (1) return NULL(LINE#1886), LINE#2098 - LINE#2100 would return. (3) As (2) has returned, LINE#2128 - LINE#2129 would do *not* give the     value to c-\u003ecache[], it means that c-\u003ecache[] is NULL.  LINE#1624 - LINE#1665 is some codes about function of cache_set_flush(). As (1), in LINE#1885 call bch_cache_set_unregister() ---\u003e bch_cache_set_stop()      ---\u003e closure_queue()           -.-\u003e cache_set_flush() (as below LINE#1624)   1624 static void cache_set_flush(struct closure *cl)  1625 {  ...  1654         for_each_cache(ca, c, i)  1655                 if (ca-\u003ealloc_thread)                           ^^  1656                         kthread_stop(ca-\u003ealloc_thread);  ...  1665 }  (4) In LINE#1655 ca is NULL(see (3)) in cache_set_flush() then the     kernel crash occurred as below: [  846.712887] bcache: register_cache() error drbd6: cannot allocate memory [  846.713242] bcache: register_bcache() error : failed to register device [  846.713336] bcache: cache_set_free() Cache set 2f84bdc1-498a-4f2f-98a7-01946bf54287 unregistered [  846.713768] BUG: unable to handle kernel NULL pointer dereference at 00000000000009f8 [  846.714790] PGD 0 P4D 0 [  846.715129] Oops: 0000 [#1] SMP PTI [  846.715472] CPU: 19 PID: 5057 Comm: kworker/19:16 Kdump: loaded Tainted: G           OE    --------- -  - 4.18.0-147.5.1.el8_1.5es.3.x86_64 #1 [  846.716082] Hardware name: ESPAN GI-25212/X11DPL-i, BIOS 2.1 06/15/2018 [  846.716451] Workqueue: events cache_set_flush [bcache] [  846.716808] RIP: 0010:cache_set_flush+0xc9/0x1b0 [bcache] [  846.717155] Code: 00 4c 89 a5 b0 03 00 00 48 8b 85 68 f6 ff ff a8 08 0f 84 88 00 00 00 31 db 66 83 bd 3c f7 ff ff 00 48 8b 85 48 ff ff ff 74 28 \u003c48\u003e 8b b8 f8 09 00 0 ---truncated---","modified":"2026-09-01T16:06:14.059415905Z","published":"2025-07-09T11:15:28.690Z","upstream":["CVE-2025-38263"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38263"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.147-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38263.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38263.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38263.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}