CVE-2025-38489: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") has accidentally removed the critical piece of commit c730fce7c70c ("s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL"), causing intermittent kernel panics in e.g. perf's on_switch() prog to reappear. Restore the fix and add a comment.
Affected products
- Linux Linux Kernel: from 6.6.26, before 6.6.100 (fixed in 6.6.100); from 6.8.5, before 6.9 (fixed in 6.9); from 6.9.1, before 6.12.40 (fixed in 6.12.40); from 6.13, before 6.15.8 (fixed in 6.15.8); version 6.9 only; version 6.16 only
Published 2025-07-28. Last modified 2026-06-17.