CVE-2025-38426: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add basic validation for RAS header If RAS header read from EEPROM is corrupted, it could result in trying to allocate huge memory for reading the records. Add some validation to header fields.

Affected products

  • Linux Linux Kernel: from 5.4, before 6.15.4 (fixed in 6.15.4)

Published 2025-07-25. Last modified 2026-06-17.