CVE-2025-38188
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38188 is a denial-of-service vulnerability in the Linux kernel's DRM/MSM Adreno a7xx GPU driver, caused by a missing CP_RESET_CONTEXT_STATE packet call during GPU context switches. The flaw was introduced during the initial a7xx GPU bringup and was publicly disclosed on July 4, 2025. Affected kernel versions include 6.7 through 6.12.34 and 6.13 through 6.15.3, as well as release candidates 6.16-rc1 and 6.16-rc2. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly).

Technical details

The root cause is an omission in the drm/msm/a7xx driver: when switching GPU contexts, the kernel fails to issue the CP_RESET_CONTEXT_STATE command packet, which is required to reset persistent GPU state used by userspace to synchronize between the BR (Binning Render) and BV (Binning Visibility) pipelines. Without this reset, state from one userspace context submission can bleed into another context, causing it to malfunction and hang. This is classified as an improper resource management issue (CWE-400/CWE-664) with a local attack vector, requiring low privileges and no user interaction. The fix was tracked via the freedesktop.org Patchwork system (Feedly, Patchwork).

Impact

Successful exploitation allows a local, low-privileged user to cause a denial of service by submitting GPU workloads in one context that cause another context to hang, effectively disrupting GPU availability for other processes or users on the same system. The vulnerability explicitly does not result in data leakage between contexts, so confidentiality and integrity are not impacted. The availability impact is rated High, affecting systems with Qualcomm Adreno a7xx GPUs running vulnerable Linux kernel versions (Feedly).

Exploitability

There is no known public proof-of-concept exploit or evidence of in-the-wild exploitation for CVE-2025-38188. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and low privileges, limiting the practical attack surface primarily to multi-tenant or shared GPU environments (Feedly).

Mitigation and workarounds

The Linux kernel maintainers have released patches addressing this vulnerability in stable branches. Fixed versions include kernel 6.12.35 and 6.15.4, and the fix is included from 6.16-rc3 onward. Patches are available at the upstream stable kernel repository. Downstream distributions including Ubuntu (USN-7833-1 through USN-7833-4, USN-7856-1) and SUSE/openSUSE have also released updated kernel packages. Users should update to a patched kernel version as soon as possible; no configuration-based workaround is available (Feedly, Ubuntu Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68480NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesAug 06, 2026
CVE-2026-64582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesAug 05, 2026
CVE-2026-64579NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-modules-internal
NoYesAug 05, 2026
CVE-2026-64576NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt
NoYesAug 05, 2026
CVE-2026-64575NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.17
NoYesAug 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management