CVE-2025-38705: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix null pointer access Writing a string without delimiters (' ', '\n', '\0') to the under gpu_od/fan_ctrl sysfs or pp_power_profile_mode for the CUSTOM profile will result in a null pointer dereference.
Affected products
- Linux Linux Kernel: before 6.12.43 (fixed in 6.12.43); from 6.13, before 6.15.11 (fixed in 6.15.11); from 6.16, before 6.16.2 (fixed in 6.16.2)
Published 2025-09-04. Last modified 2026-06-17.