CVE-2025-38409

Source
https://cve.org/CVERecord?id=CVE-2025-38409
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38409.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38409
Downstream
Related
Published
2025-07-25T13:20:14.229Z
Modified
2026-05-28T03:55:08.948232205Z
Summary
drm/msm: Fix another leak in the submit error path
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/msm: Fix another leak in the submit error path

putunusedfd() doesn't free the installed file, if we've already done fdinstall(). So we need to also free the syncfile.

Patchwork: https://patchwork.freedesktop.org/patch/653583/

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38409.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0cf6c71d70d8aa39b8fd0e39c9009602a0e0d300
Fixed
00b3401f692082ddf6342500d1be25560bba46d4
Fixed
c40ad1c04d306f7fde26337fdcf8a5979657d93f
Fixed
3f6ce8433a9035b0aa810e1f5b708e9dc1c367b0
Fixed
30d3819b0b9173e31b84d662a592af8bad351427
Fixed
f681c2aa8676a890eacc84044717ab0fd26e058f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38409.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.12.0
Fixed
6.1.144
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.97
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.37
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38409.json"