
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38371 is a vulnerability in the Linux kernel's DRM/V3D driver discovered and disclosed on July 25, 2025. The vulnerability affects the GPU interrupt handling during reset operations in the Linux kernel (NVD).
The vulnerability occurs when an interrupt can be triggered during a GPU reset, which can lead to GPU hangs and NULL pointer dereference in an interrupt context. This results in a level 1 translation fault and subsequent kernel panic. The issue specifically manifests in the v3d_irq handler during GPU reset operations (NVD).
When exploited, this vulnerability can cause a kernel panic through a NULL pointer dereference, leading to system instability and potential denial of service. The issue affects systems running the Linux kernel with the V3D GPU driver enabled, particularly impacting Raspberry Pi 4 hardware (NVD).
The vulnerability has been resolved by implementing a fix that disables interrupts before resetting the GPU, preventing the race condition that leads to the NULL pointer dereference (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."