CVE-2025-38429 is a medium-severity vulnerability in the Linux kernel's MHI bus driver, specifically affecting the mhi_ep_ring_add_element function. It involves a race condition where the read pointer is updated before the buffer is fully written, potentially leading to data corruption if a host accesses an incomplete or uninitialized element. The vulnerability has a CVSS score of 5.5 (MEDIUM) with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating it requires local access with low attack complexity and can lead to high availability impact. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, it has garnered some community discussion and media coverage, primarily through Ubuntu security advisories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.19, < 6.6.95CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.35CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.15.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026kernel: bus: mhi: ep: Update read pointer only after buffer is written
Jul 25, 2025bus: mhi: ep: Update read pointer only after buffer is written
Jul 8, 2025