drm/panthor: Fix UAF in panthor_gem_create_with_handle() debugfs code
Published Aug 19, 2025
7.8
HIGHCVSS 3.1
EPSS 0.16%
Description
The object is potentially already gone after the drm_gem_object_put(). In general the object should be fully constructed before calling drm_gem_handle_create(), except the debugfs tracking uses a separate lock and list and separate flag to denotate whether the object is actually initialized.
Since I'm touching this all anyway simplify this by only adding the object to the debugfs when it's ready for that, which allows us to delete that separate flag. panthor_gem_debugfs_bo_rm() already checks whether we've actually been added to the list or this is some error path cleanup.
v2: Fix build issues for !CONFIG_DEBUGFS (Adrián)
v3: Add linebreak and remove outdated comment (Liviu)
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.16
- Version 6.16.1StatusunaffectedConstraints<=6.16.*
- Version 6.17StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- 6.16
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.16% (0.00158) | 4.34th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.14% (0.00143) | 3.90th | v5 (v2026.06.15) |
| Aug 20, 2025 | 0.02% (0.00018) | 3.00th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/security/cve/CVE-2025-38596 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2389482 Issue Tracking
- https://git.kernel.org/stable/c/5f2be12442db6a2904e6e31b0e3b5ad5aebf868b Patch
- https://git.kernel.org/stable/c/fe69a391808404977b1f002a6e7447de3de7a88e Patch
- https://lore.kernel.org/linux-cve-announce/2025081919-CVE-2025-38596-9c29@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-38596
- https://www.cve.org/CVERecord?id=CVE-2025-38596
Change history (0)
No recorded changes yet.