Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-65738.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-65738
Upstream
Published
2025-07-25T13:15:29Z
Modified
2026-04-01T05:20:38.117920Z
Summary
CVE-2025-38401 affecting package kernel for versions less than 6.6.104.2-1
Details

In the Linux kernel, the following vulnerability has been resolved:

mtk-sd: Prevent memory corruption from DMA map failure

If msdcpreparedata() fails to map the DMA region, the request is not prepared for data receiving, but msdcstartdata() proceeds the DMA with previous setting. Since this will lead a memory corruption, we have to stop the request operation soon after the msdcpreparedata() fails to prepare it.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.104.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-65738.json"