Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38696

18
FAUCET Score

CVE-2025-38696 is a null pointer dereference vulnerability in the Linux kernel's MIPS architecture, specifically affecting tasks without an associated ABI or vDSO, such as kthreads. This flaw can lead to a system crash when the stack_top() function is called, impacting various Debian and Linux kernel versions. Rated as Medium severity (CVSS 5.5), it requires local access and low privileges (AV:L/PR:L) to trigger, resulting in high availability impact (A:H) but no confidentiality or integrity loss. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.14.77, < 4.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.18.15, < 4.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.19.1, < 5.4.297CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.241CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 38th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

microsoftpatch availablevia msrc
Product: 20412-17084Fixed in: 6.6.104.2-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.96.2-2 on Azure Linux 3.0Fixed in: 6.6.104.2-1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
microsoft2025-Sep/CVE-2025-38696

MIPS: Don't crash in stack_top() for tasks without ABI or vDSO

Sep 9, 2025
redhatCVE-2025-38696

kernel: MIPS: Don't crash in stack_top() for tasks without ABI or vDSO

Sep 4, 2025

References

cert-portal.siemens.com / productcert/html/ssa-032379.html
git.kernel.org / stable/c/24d098b6f69b0aa806ffcb3e18259bee31650b28
Patch
git.kernel.org / stable/c/5b6839b572b503609b9b58bc6c04a816eefa0794
Patch
git.kernel.org / stable/c/82d140f6aab5e89a9d3972697a0dbe1498752d9b
Patch
git.kernel.org / stable/c/ab18e48a503230d675e824a0d68a108bdff42503
Patch
git.kernel.org / stable/c/bd90dbd196831f5c2620736dc221db2634cf1e8e
Patch
git.kernel.org / stable/c/cddf47d20b0325dc8a4e57b833fe96e8f36c42a4
Patch
git.kernel.org / stable/c/e78033e59444d257d095b73ce5d20625294f6ec2
Patch
git.kernel.org / stable/c/e9f4a6b3421e936c3ee9d74710243897d74dbaa2
Patch
git.kernel.org / stable/c/f22de2027b206ddfb8a075800bb5d0dacf2da4b8
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory