Wind River Support Network

HomeDefectsLIN1023-13638
Acknowledged

LIN1023-13638 : Security Advisory - linux - CVE-2025-38071

Created: Jun 19, 2025    Updated: Jun 20, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:EOL][EOL]x86/mm: Check return value from memblock_phys_alloc_range()[EOL][EOL]At least with CONFIG_PHYSICAL_START=0x100000, if there is < 4 MiB of[EOL]contiguous free memory available at this point, the kernel will crash[EOL]and burn because memblock_phys_alloc_range() returns 0 on failure,[EOL]which leads memblock_phys_free() to throw the first 4 MiB of physical[EOL]memory to the wolves.[EOL][EOL]At a minimum it should fail gracefully with a meaningful diagnostic,[EOL]but in fact everything seems to work fine without the weird reserve[EOL]allocation.

CREATE(Triage):(User=lchen-cn) [CVE-2025-38071 (https://nvd.nist.gov/vuln/detail/CVE-2025-38071)
Live chat
Online