
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38188 is a denial-of-service vulnerability in the Linux kernel's DRM/MSM Adreno a7xx GPU driver, caused by a missing CP_RESET_CONTEXT_STATE packet call during GPU context switches. The flaw was introduced during the initial a7xx GPU bringup and was publicly disclosed on July 4, 2025. Affected kernel versions include 6.7 through 6.12.34 and 6.13 through 6.15.3, as well as release candidates 6.16-rc1 and 6.16-rc2. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly).
The root cause is an omission in the drm/msm/a7xx driver: when switching GPU contexts, the kernel fails to issue the CP_RESET_CONTEXT_STATE command packet, which is required to reset persistent GPU state used by userspace to synchronize between the BR (Binning Render) and BV (Binning Visibility) pipelines. Without this reset, state from one userspace context submission can bleed into another context, causing it to malfunction and hang. This is classified as an improper resource management issue (CWE-400/CWE-664) with a local attack vector, requiring low privileges and no user interaction. The fix was tracked via the freedesktop.org Patchwork system (Feedly, Patchwork).
Successful exploitation allows a local, low-privileged user to cause a denial of service by submitting GPU workloads in one context that cause another context to hang, effectively disrupting GPU availability for other processes or users on the same system. The vulnerability explicitly does not result in data leakage between contexts, so confidentiality and integrity are not impacted. The availability impact is rated High, affecting systems with Qualcomm Adreno a7xx GPUs running vulnerable Linux kernel versions (Feedly).
There is no known public proof-of-concept exploit or evidence of in-the-wild exploitation for CVE-2025-38188. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and low privileges, limiting the practical attack surface primarily to multi-tenant or shared GPU environments (Feedly).
The Linux kernel maintainers have released patches addressing this vulnerability in stable branches. Fixed versions include kernel 6.12.35 and 6.15.4, and the fix is included from 6.16-rc3 onward. Patches are available at the upstream stable kernel repository. Downstream distributions including Ubuntu (USN-7833-1 through USN-7833-4, USN-7856-1) and SUSE/openSUSE have also released updated kernel packages. Users should update to a patched kernel version as soon as possible; no configuration-based workaround is available (Feedly, Ubuntu Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."