CVE-2025-38265

Source
https://cve.org/CVERecord?id=CVE-2025-38265
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38265.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38265
Downstream
Related
Published
2025-07-10T07:37:33.778Z
Modified
2026-05-15T11:54:11.785589628Z
Summary
serial: jsm: fix NPE during jsm_uart_port_init
Details

In the Linux kernel, the following vulnerability has been resolved:

serial: jsm: fix NPE during jsmuartport_init

No device was set which caused serialbasectrl_add to crash.

BUG: kernel NULL pointer dereference, address: 0000000000000050 Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 16 UID: 0 PID: 368 Comm: (udev-worker) Not tainted 6.12.25-amd64 #1 Debian 6.12.25-1 RIP: 0010:serialbasectrladd+0x96/0x120 Call Trace: <TASK> serialcoreregisterport+0x1a0/0x580 ? __setup_irq+0x39c/0x660 ? __kmalloccachenoprof+0x111/0x310 jsmuartportinit+0xe8/0x180 [jsm] jsmprobeone+0x1f4/0x410 [jsm] localpciprobe+0x42/0x90 pcideviceprobe+0x22f/0x270 reallyprobe+0xdb/0x340 ? pmruntimebarrier+0x54/0x90 ? pfxdriverattach+0x10/0x10 __driverprobedevice+0x78/0x110 driverprobedevice+0x1f/0xa0 __driverattach+0xba/0x1c0 busfor_eachdev+0x8c/0xe0 busadddriver+0x112/0x1f0 driverregister+0x72/0xd0 jsminitmodule+0x36/0xff0 [jsm] ? _pfxjsminitmodule+0x10/0x10 [jsm] dooneinitcall+0x58/0x310 doinitmodule+0x60/0x230

Tested with Digi Neo PCIe 8 port card.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38265.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.6.94
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.33
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.14.11
Type
ECOSYSTEM
Events
Introduced
6.15.0
Fixed
6.15.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38265.json"