CVE-2025-38362: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null pointer check for get_first_active_display() The function mod_hdcp_hdcp1_enable_encryption() calls the function get_first_active_display(), but does not check its return value. The return value is a null pointer if the display list is empty. This will lead to a null pointer dereference in mod_hdcp_hdcp2_enable_encryption(). Add a null pointer check for get_first_active_display() and return MOD_HDCP_STATUS_DISPLAY_NOT_FOUND if the function return null.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 5.8, before 5.15.187 (fixed in 5.15.187); from 5.16, before 6.1.143 (fixed in 6.1.143); from 6.2, before 6.6.96 (fixed in 6.6.96); from 6.7, before 6.12.36 (fixed in 6.12.36); from 6.13, before 6.15.5 (fixed in 6.15.5)

Published 2025-07-25. Last modified 2026-06-17.