Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38565

24
FAUCET Score

CVE-2025-38565 is a high-severity vulnerability in the Linux kernel's perf subsystem, affecting Debian and other Linux distributions. It involves a reference count leak in perf_rdpmc_allowed on X86 systems when perf_mmap() fails, leading to potential resource exhaustion. With a CVSS score of 7.8, this local vulnerability requires low privileges and user interaction, but could result in high confidentiality, integrity, and availability impacts. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0, < 5.4.297CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.241CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.148CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.102CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 31st percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 20412-17084Fixed in: 6.6.104.2-1
microsoftpatch availablevia msrc
Product: 17087-17086Fixed in: 5.15.200.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.96.2-2 on Azure Linux 3.0Fixed in: 6.6.104.2-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0Fixed in: 5.15.200.1-1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel

Vendor Advisories (2)

redhatCVE-2025-38565Low

kernel: perf/core: Exit early on perf_mmap() fail

Aug 19, 2025
microsoft2025-Aug/CVE-2025-38565

perf/core: Exit early on perf_mmap() fail

Aug 12, 2025

References

git.kernel.org / stable/c/07091aade394f690e7b655578140ef84d0e8d7b0
Patch
git.kernel.org / stable/c/163b0d1a209fe0df5476c1df2330ca12b55abf92
Patch
git.kernel.org / stable/c/27d44145bd576bbef9bf6165bcd78128ec3e6cbd
Patch
git.kernel.org / stable/c/5ffda7f3ed76ec8defc19d985e33b3b82ba07839
Patch
git.kernel.org / stable/c/7ff8521f30c4c2fcd4e88bd7640486602bf8a650
Patch
git.kernel.org / stable/c/92043120a2e992800580855498ab8507e1b22db9
Patch
git.kernel.org / stable/c/9b90a48c7de828a15c7a4fc565d46999c6e22d6b
Patch
git.kernel.org / stable/c/de85e72598d89880a02170a1cbc27b35a7d978a9
Patch
git.kernel.org / stable/c/f41e9eba77bf97626e04296dc5677d02816d2432
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory