SB2025082889 - Improper error handling in Linux kernel powerpc kernel
Published: August 28, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper error handling (CVE-ID: CVE-2025-38623)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the pnv_php_set_attention_state(), pnv_php_enable() and pnv_php_enable_msix() functions in drivers/pci/hotplug/pnv_php.c, within the pci_hp_add_devices() function in arch/powerpc/kernel/pci-hotplug.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1d2f63680c5719a5da92639e981c6c9a87fcee08
- https://git.kernel.org/stable/c/473999ba937eac9776be791deed7c84a21d7880b
- https://git.kernel.org/stable/c/48c6935a34981bb56f35be0774ec1f30c6e386f8
- https://git.kernel.org/stable/c/6e7b24c71e530a6c1d656e73d8a30ee081656844
- https://git.kernel.org/stable/c/78d20b8c13075eae3d884c21db7a09a6bbdda5b2
- https://git.kernel.org/stable/c/a2a2a6fc2469524caa713036297c542746d148dc