CVE-2025-38409: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix another leak in the submit error path put_unused_fd() doesn't free the installed file, if we've already done fd_install(). So we need to also free the sync_file. Patchwork: https://patchwork.freedesktop.org/patch/653583/
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: from 3.12, before 6.1.144 (fixed in 6.1.144); from 6.2, before 6.6.97 (fixed in 6.6.97); from 6.7, before 6.12.37 (fixed in 6.12.37); from 6.13, before 6.15.6 (fixed in 6.15.6); version 6.16 only
Published 2025-07-25. Last modified 2026-06-17.