Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66530.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-66530
Upstream
Published
2025-08-19T17:15:35Z
Modified
2026-04-01T05:20:59.686010Z
Summary
CVE-2025-38583 affecting package kernel for versions less than 6.6.104.2-1
Details

In the Linux kernel, the following vulnerability has been resolved:

clk: xilinx: vcu: unregister pll_post only if registered correctly

If registration of pll_post is failed, it will be set to NULL or ERR, unregistering same will fail with following call trace:

Unable to handle kernel NULL pointer dereference at virtual address 008 pc : clkhwunregister+0xc/0x20 lr : clkhwunregisterfixedfactor+0x18/0x30 sp : ffff800011923850 ... Call trace: clkhwunregister+0xc/0x20 clkhwunregisterfixedfactor+0x18/0x30 xvcuunregisterclockprovider+0xcc/0xf4 [xlnxvcu] xvcuprobe+0x2bc/0x53c [xlnxvcu]

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.104.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66530.json"