CVE-2025-38152
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
[CVE-2025-38152]: A vulnerability affecting Linux kernel's remoteproc subsystem has been identified and resolved on i.MX8MP and i.MX9 platforms. This issue arises when the rproc module is shut down without updating the rproc->table_sz value. Subsequently, when starting an rproc with firmware lacking a resource table, a NULL pointer dereference occurs, triggering a kernel dump. The vulnerability can be exploited by manipulating the rproc's resource table, leading to potential privilege escalation or denial of service attacks. To address this issue, it is recommended that the rproc module's table_sz value be cleared when it is shut down.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.