CVE-2025-38705

Source
https://cve.org/CVERecord?id=CVE-2025-38705
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38705.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38705
Downstream
Related
Published
2025-09-04T15:32:56.634Z
Modified
2026-05-18T05:59:31.083668125Z
Summary
drm/amd/pm: fix null pointer access
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/pm: fix null pointer access

Writing a string without delimiters (' ', '\n', '\0') to the under gpuod/fanctrl sysfs or pppowerprofile_mode for the CUSTOM profile will result in a null pointer dereference.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38705.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
37c5c4dbf03b167b5ca68d4bbc7fb6c92a463fb4
Fixed
a83ffafd02a7af59848755c109d544e3894af737
Fixed
5d8cc029e5595760c7d18c64632e8e40a86a9b2e
Fixed
cef79c18538e9ce2ca6e5b3fa95c38ec41dcd07a
Fixed
d524d40e3a6152a3ea1125af729f8cd8ca65efde

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38705.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
6.12.43
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.11
Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.16.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38705.json"