Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38262

17
FAUCET Score

CVE-2025-38262 is a concurrency race vulnerability in the Linux kernel's uartlite serial driver, affecting Debian and other Linux distributions. This flaw can lead to a kernel panic due to a null pointer dereference when two uart devices probe simultaneously. Rated Medium (CVSS 5.5), it requires local access (AV:L, PR:L) and has a high impact on availability (A:H) with low attack complexity (AC:L). There is no evidence of active exploitation or public exploit code, though it has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.20, < 5.4.296CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.15.187CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.143CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.96CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.12.36CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 28th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0Fixed in: 5.15.200.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.92.2-2 on Azure Linux 3.0Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: 17087-17086Fixed in: 5.15.200.1-1
microsoftpatch availablevia msrc
Product: 19880-17084Fixed in: 6.6.96.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
grafanavendor investigatingvia llm_extracted
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (8)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
grafanallm-grafana-3bfe68bd8f94bc6dCRITICAL

HP ThinPro 8.1 SP9 Security Updates

Feb 2, 2026
redhatCVE-2025-38262Moderate

kernel: tty: serial: uartlite: register uart driver in init

Jul 9, 2025
microsoft2025-Jul/CVE-2025-38262Moderate

tty: serial: uartlite: register uart driver in init

Jul 8, 2025

References

git.kernel.org / stable/c/5015eed450005bab6e5cb6810f7a62eab0434fc4
Patch
git.kernel.org / stable/c/685d29f2c5057b32c7b1b46f2a7d303b926c8f72
Patch
git.kernel.org / stable/c/6bd697b5fc39fd24e2aa418c7b7d14469f550a93
Patch
git.kernel.org / stable/c/6db06aaea07bb7c8e33a425cf7b98bf29ee6056e
Patch
git.kernel.org / stable/c/8e958d10dd0ce5ae674cce460db5c9ca3f25243b
Patch
git.kernel.org / stable/c/9c905fdbba68a6d73d39a6b7de9b9f0d6c46df87
Patch
git.kernel.org / stable/c/f5e4229d94792b40e750f30c92bcf7a3107c72ef
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory