Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38263

17
FAUCET Score

CVE-2025-38263 addresses a NULL pointer dereference vulnerability in the Linux kernel's bcache subsystem. Specifically, during the initialization of a cache set, if memory allocation fails, a NULL pointer can be passed to the cache_set_flush function, leading to a kernel crash. This vulnerability impacts various Linux distributions, including Debian and Ubuntu. The severity is rated as Medium (CVSS 5.5), indicating a local attack vector with low complexity. An attacker with local privileges could trigger a denial-of-service condition by causing the kernel to crash. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit or ExploitDB. The vulnerability has garnered some community discussion and media coverage, primarily through Ubuntu security advisories.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.10, < 5.10.240CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.187CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.143CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.96CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.12.36CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 28th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.92.2-2 on Azure Linux 3.0Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: 19880-17084Fixed in: 6.6.96.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
grafanavendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
grafanallm-grafana-3bfe68bd8f94bc6dCRITICAL

HP ThinPro 8.1 SP9 Security Updates

Feb 2, 2026
redhatCVE-2025-38263Moderate

kernel: bcache: fix NULL pointer in cache_set_flush()

Jul 9, 2025
microsoft2025-Jul/CVE-2025-38263Moderate

bcache: fix NULL pointer in cache_set_flush()

Jul 8, 2025

References

git.kernel.org / stable/c/1e46ed947ec658f89f1a910d880cd05e42d3763e
Patch
git.kernel.org / stable/c/1f25f2d3fa29325320c19a30abf787e0bd5fc91b
Patch
git.kernel.org / stable/c/3f9e128186c99a117e304f1dce6d0b9e50c63cd8
Patch
git.kernel.org / stable/c/553f560e0a74a7008ad9dba05c3fd05da296befb
Patch
git.kernel.org / stable/c/667c3f52373ff5354cb3543e27237eb7df7b2333
Patch
git.kernel.org / stable/c/c4f5e7e417034b05f5d2f5fa9a872db897da69bd
Patch
git.kernel.org / stable/c/d54681938b777488e5dfb781b566d16adad991de
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory