CVE-2025-38633
Linux Ubuntu vulnerability analysis and mitigation

Overview

CVE-2025-38633 is a vulnerability discovered in the Linux kernel affecting the clock management system, specifically the spacemit clock driver. The vulnerability was disclosed on August 22, 2025, and involves the pll1_d8 clock, which is enabled by the boot loader and serves as a parent for numerous critical system clocks, including those used by APB and AXI buses (NVD).

Technical details

The vulnerability occurs when the pll1_d8 clock gets disabled while responding to a -EPROBE_DEFER error when requesting a reset controller. The issue manifests when CLK_DMA clock (along with its parents) is enabled but then gets disabled in response to the probe deferral. This action causes parent clocks to reduce their enable count, and when pll1_d8's count reaches zero, it becomes disabled, leading to a system hang. The fix involves marking the clock as critical to prevent it from being disabled and defining a new macro CCU_FACTOR_GATE_DEFINE() to allow clock flags to be supplied for a CCU_FACTOR_GATE clock (NVD).

Impact

When exploited, this vulnerability can cause a complete system hang due to the disabling of critical system clocks that are essential for APB and AXI buses operation. This can result in system-wide disruption and potential denial of service (NVD).

Mitigation and workarounds

The vulnerability has been resolved by marking the pll1_d8 clock as critical, which prevents it from being disabled. Additionally, a new macro CCU_FACTOR_GATE_DEFINE() has been implemented to properly handle clock flags for CCU_FACTOR_GATE clocks (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24528HIGH7.1
  • KerberosKerberos
  • crypto-policies
NoYesJan 16, 2026
CVE-2025-24531MEDIUM6.7
  • Linux DebianLinux Debian
  • pam-pkcs11
NoYesJan 16, 2026
CVE-2025-43904MEDIUM4.2
  • Linux DebianLinux Debian
  • slurm_22_05-munge
NoYesJan 16, 2026
CVE-2025-71144N/AN/A
  • Linux DebianLinux Debian
  • linux-azure-fips
NoYesJan 14, 2026
CVE-2025-71143N/AN/A
  • Linux DebianLinux Debian
  • linux-oem-6.14
NoNoJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management