{"id":"DEBIAN-CVE-2025-38387","details":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx5: Initialize obj_event-\u003eobj_sub_list before xa_insert  The obj_event may be loaded immediately after inserted, then if the list_head is not initialized then we may get a poisonous pointer.  This fixes the crash below:   mlx5_core 0000:03:00.0: MLX5E: StrdRq(1) RqSz(8) StrdSz(2048) RxCqeCmprss(0 enhanced)  mlx5_core.sf mlx5_core.sf.4: firmware version: 32.38.3056  mlx5_core 0000:03:00.0 en3f0pf0sf2002: renamed from eth0  mlx5_core.sf mlx5_core.sf.4: Rate limit: 127 rates are supported, range: 0Mbps to 195312Mbps  IPv6: ADDRCONF(NETDEV_CHANGE): en3f0pf0sf2002: link becomes ready  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000060  Mem abort info:    ESR = 0x96000006    EC = 0x25: DABT (current EL), IL = 32 bits    SET = 0, FnV = 0    EA = 0, S1PTW = 0  Data abort info:    ISV = 0, ISS = 0x00000006    CM = 0, WnR = 0  user pgtable: 4k pages, 48-bit VAs, pgdp=00000007760fb000  [0000000000000060] pgd=000000076f6d7003, p4d=000000076f6d7003, pud=0000000777841003, pmd=0000000000000000  Internal error: Oops: 96000006 [#1] SMP  Modules linked in: ipmb_host(OE) act_mirred(E) cls_flower(E) sch_ingress(E) mptcp_diag(E) udp_diag(E) raw_diag(E) unix_diag(E) tcp_diag(E) inet_diag(E) binfmt_misc(E) bonding(OE) rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) isofs(E) cdrom(E) mst_pciconf(OE) ib_umad(OE) mlx5_ib(OE) ipmb_dev_int(OE) mlx5_core(OE) kpatch_15237886(OEK) mlxdevm(OE) auxiliary(OE) ib_uverbs(OE) ib_core(OE) psample(E) mlxfw(OE) tls(E) sunrpc(E) vfat(E) fat(E) crct10dif_ce(E) ghash_ce(E) sha1_ce(E) sbsa_gwdt(E) virtio_console(E) ext4(E) mbcache(E) jbd2(E) xfs(E) libcrc32c(E) mmc_block(E) virtio_net(E) net_failover(E) failover(E) sha2_ce(E) sha256_arm64(E) nvme(OE) nvme_core(OE) gpio_mlxbf3(OE) mlx_compat(OE) mlxbf_pmc(OE) i2c_mlxbf(OE) sdhci_of_dwcmshc(OE) pinctrl_mlxbf3(OE) mlxbf_pka(OE) gpio_generic(E) i2c_core(E) mmc_core(E) mlxbf_gige(OE) vitesse(E) pwr_mlxbf(OE) mlxbf_tmfifo(OE) micrel(E) mlxbf_bootctl(OE) virtio_ring(E) virtio(E) ipmi_devintf(E) ipmi_msghandler(E)   [last unloaded: mst_pci]  CPU: 11 PID: 20913 Comm: rte-worker-11 Kdump: loaded Tainted: G           OE K   5.10.134-13.1.an8.aarch64 #1  Hardware name: https://www.mellanox.com BlueField-3 SmartNIC Main Card/BlueField-3 SmartNIC Main Card, BIOS 4.2.2.12968 Oct 26 2023  pstate: a0400089 (NzCv daIf +PAN -UAO -TCO BTYPE=--)  pc : dispatch_event_fd+0x68/0x300 [mlx5_ib]  lr : devx_event_notifier+0xcc/0x228 [mlx5_ib]  sp : ffff80001005bcf0  x29: ffff80001005bcf0 x28: 0000000000000001  x27: ffff244e0740a1d8 x26: ffff244e0740a1d0  x25: ffffda56beff5ae0 x24: ffffda56bf911618  x23: ffff244e0596a480 x22: ffff244e0596a480  x21: ffff244d8312ad90 x20: ffff244e0596a480  x19: fffffffffffffff0 x18: 0000000000000000  x17: 0000000000000000 x16: ffffda56be66d620  x15: 0000000000000000 x14: 0000000000000000  x13: 0000000000000000 x12: 0000000000000000  x11: 0000000000000040 x10: ffffda56bfcafb50  x9 : ffffda5655c25f2c x8 : 0000000000000010  x7 : 0000000000000000 x6 : ffff24545a2e24b8  x5 : 0000000000000003 x4 : ffff80001005bd28  x3 : 0000000000000000 x2 : 0000000000000000  x1 : ffff244e0596a480 x0 : ffff244d8312ad90  Call trace:   dispatch_event_fd+0x68/0x300 [mlx5_ib]   devx_event_notifier+0xcc/0x228 [mlx5_ib]   atomic_notifier_call_chain+0x58/0x80   mlx5_eq_async_int+0x148/0x2b0 [mlx5_core]   atomic_notifier_call_chain+0x58/0x80   irq_int_handler+0x20/0x30 [mlx5_core]   __handle_irq_event_percpu+0x60/0x220   handle_irq_event_percpu+0x3c/0x90   handle_irq_event+0x58/0x158   handle_fasteoi_irq+0xfc/0x188   generic_handle_irq+0x34/0x48   ...","modified":"2026-09-01T16:06:14.365990896Z","published":"2025-07-25T13:15:28Z","upstream":["CVE-2025-38387"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38387"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.147-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38387.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38387.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38387.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}