SB2025071101 - Use-after-free in Linux kernel allwinner sun8i-ce driver
Published: July 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2025-38300)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the drivers/crypto/allwinner/sun8i-ce/sun8i-ce-cipher.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/19d267d9fad00d94ad8477899e38ed7c11f33fb6
- https://git.kernel.org/stable/c/4051250e5db489f8ad65fc337e2677b9b568ac72
- https://git.kernel.org/stable/c/a0ac3f85b2e3ef529e852f252a70311f9029d5e6
- https://git.kernel.org/stable/c/c62b79c1c51303dbcb6edfa4de0ee176f4934c52
- https://git.kernel.org/stable/c/f31adc3e356f7350d4a4d68c98d3f60f2f6e26b3