{"id":"DEBIAN-CVE-2025-38419","details":"In the Linux kernel, the following vulnerability has been resolved:  remoteproc: core: Cleanup acquired resources when rproc_handle_resources() fails in rproc_attach()  When rproc-\u003estate = RPROC_DETACHED and rproc_attach() is used to attach to the remote processor, if rproc_handle_resources() returns a failure, the resources allocated by imx_rproc_prepare() should be released, otherwise the following memory leak will occur.  Since almost the same thing is done in imx_rproc_prepare() and rproc_resource_cleanup(), Function rproc_resource_cleanup() is able to deal with empty lists so it is better to fix the \"goto\" statements in rproc_attach(). replace the \"unprepare_device\" goto statement with \"clean_up_resources\" and get rid of the \"unprepare_device\" label.  unreferenced object 0xffff0000861c5d00 (size 128): comm \"kworker/u12:3\", pid 59, jiffies 4294893509 (age 149.220s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 02 88 00 00 00 00 00 00 10 00 00 00 00 00 ............ backtrace:  [\u003c00000000f949fe18\u003e] slab_post_alloc_hook+0x98/0x37c  [\u003c00000000adbfb3e7\u003e] __kmem_cache_alloc_node+0x138/0x2e0  [\u003c00000000521c0345\u003e] kmalloc_trace+0x40/0x158  [\u003c000000004e330a49\u003e] rproc_mem_entry_init+0x60/0xf8  [\u003c000000002815755e\u003e] imx_rproc_prepare+0xe0/0x180  [\u003c0000000003f61b4e\u003e] rproc_boot+0x2ec/0x528  [\u003c00000000e7e994ac\u003e] rproc_add+0x124/0x17c  [\u003c0000000048594076\u003e] imx_rproc_probe+0x4ec/0x5d4  [\u003c00000000efc298a1\u003e] platform_probe+0x68/0xd8  [\u003c00000000110be6fe\u003e] really_probe+0x110/0x27c  [\u003c00000000e245c0ae\u003e] __driver_probe_device+0x78/0x12c  [\u003c00000000f61f6f5e\u003e] driver_probe_device+0x3c/0x118  [\u003c00000000a7874938\u003e] __device_attach_driver+0xb8/0xf8  [\u003c0000000065319e69\u003e] bus_for_each_drv+0x84/0xe4  [\u003c00000000db3eb243\u003e] __device_attach+0xfc/0x18c  [\u003c0000000072e4e1a4\u003e] device_initial_probe+0x14/0x20","modified":"2026-09-01T16:06:14.438348816Z","published":"2025-07-25T14:15:33.727Z","upstream":["CVE-2025-38419"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38419"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.147-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38419.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38419.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38419.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}