CVE-2025-38062
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38062 is a vulnerability discovered in the Linux kernel related to the IOMMU translation for MSI message addresses. The vulnerability was disclosed on June 18, 2025, and affects the kernel's handling of MSI (Message Signaled Interrupts) descriptors (NVD, Wiz).

Technical details

The vulnerability stems from a two-step process in IOMMU translation for MSI message addresses: first, iommu_dma_prepare_msi() stores a cookie pointer containing the IOVA address in the MSI descriptor during interrupt allocation, and second, iommu_dma_compose_msi_msg() uses this cookie pointer to compute a translated message address. This process has an inherent lifetime problem for the pointer stored in the cookie that must remain valid between the two steps, with no locking at the irq layer to protect the lifetime (NVD).

Impact

The vulnerability could potentially lead to Use-After-Free (UAF) conditions in two scenarios: the cookie pointer and the unlocked call to iommu_get_domain_for_dev() on the MSI translation path. This occurs particularly when the iommu domain can be changed during VFIO operation (Wiz).

Mitigation and workarounds

The vulnerability has been fixed by removing the cookie pointer and storing the translated IOVA address directly as an integer in the MSI descriptor, as this address is already known during iommu_dma_prepare_msi() and cannot change. The additional UAF related to iommu_get_domain_for_dev() is addressed in a separate patch that implements the IOMMU group mutex (Wiz).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-oem-6.14
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-core
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • linux-aws-fips
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management