CVE-2025-38696
CBL Mariner vulnerability analysis and mitigation

Overview

CVE-2025-38696 is a vulnerability discovered in the Linux kernel affecting MIPS architecture systems. The issue was publicly disclosed on September 4, 2025, and involves a crash condition in the stack_top() function when handling tasks without ABI or vDSO mappings (NVD, Ubuntu).

Technical details

The vulnerability occurs when tasks without an associated ABI or virtual dynamic shared object (vDSO) mapping attempt to call the stack_top() function. This particularly affects kernel threads (kthreads) which never have these mappings. When such a task calls stack_top(), it attempts to dereference a NULL ABI pointer, resulting in a system crash. The issue can be triggered during kunit testing operations through a specific call chain involving mips_stack_top, arch_pick_mmap_layout, and several other kernel functions (NVD).

Impact

The vulnerability can cause system crashes when specific kernel operations are performed, particularly affecting systems running kunit tests. This primarily impacts MIPS architecture systems running the Linux kernel (NVD).

Mitigation and workarounds

The fix involves modifying the code to only dereference the ABI pointer if it is set. Additionally, the GIC page handling has been updated as it is specific to the vDSO, and the randomization adjustment has been moved into the same conditional block (NVD).

Additional resources


SourceThis report was generated using AI

Related CBL Mariner vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68973HIGH7
  • NixOSNixOS
  • gnupg2-scdaemon
NoYesDec 28, 2025
CVE-2025-13699HIGH7
  • MariaDB ServerMariaDB Server
  • mariadb1011-server-utils
NoYesDec 23, 2025
CVE-2025-68343MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-debug
NoYesDec 23, 2025
CVE-2025-68972MEDIUM4.7
  • NixOSNixOS
  • gnupg2-dirmngr
NoYesDec 27, 2025
CVE-2025-11961LOW1.9
  • CBL MarinerCBL Mariner
  • libpcap-debugsource
NoYesDec 31, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management