CVE-2025-38535
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38535 is a vulnerability discovered in the Linux kernel affecting the UTMI PHY mode in the Tegra XUSB driver. The issue was disclosed on August 16, 2025, and involves an unbalanced regulator disable operation when transitioning between USB roles (NVD, RedHat).

Technical details

The vulnerability occurs when transitioning from USB_ROLE_DEVICE to USB_ROLE_NONE state, where the code incorrectly assumes that the regulator should be disabled. For regulators marked as always-on, the regulator_is_enabled() function continues to return true, leading to an improper attempt to disable an already-enabled regulator. The issue has been assigned a CVSS v3.1 score of 7.0 (High) with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (RedHat).

Impact

The vulnerability results in system warnings and potential regulator state inconsistencies. Specifically, it can trigger warnings such as 'WARNING: CPU: 1 PID: 7326 at drivers/regulator/core.c:3004 _regulator_disable+0xe4/0x1a0' and 'unbalanced disables for VIN_SYS_5V0' (NVD).

Mitigation and workarounds

The fix involves moving the regulator control logic into the tegra186_xusb_padctl_id_override() function, ensuring that the regulator is only disabled when transitioning from USB_ROLE_HOST to USB_ROLE_NONE by checking the VBUS_ID register. This change ensures properly balanced regulator enable/disable operations. Fixed versions are available in Linux kernel 6.16.3-1 for Debian Forky/Sid, 6.12.41-1 for Debian Trixie, and 6.1.147-1 for Debian Bookworm (Debian).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt-addons
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-core
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • linux-ibm-5.15
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management