We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-38210

configfs-tsm-report: Fix NULL dereference of tsm_ops



Description

In the Linux kernel, the following vulnerability has been resolved: configfs-tsm-report: Fix NULL dereference of tsm_ops Unlike sysfs, the lifetime of configfs objects is controlled by userspace. There is no mechanism for the kernel to find and delete all created config-items. Instead, the configfs-tsm-report mechanism has an expectation that tsm_unregister() can happen at any time and cause established config-item access to start failing. That expectation is not fully satisfied. While tsm_report_read(), tsm_report_{is,is_bin}_visible(), and tsm_report_make_item() safely fail if tsm_ops have been unregistered, tsm_report_privlevel_store() tsm_report_provider_show() fail to check for ops registration. Add the missing checks for tsm_ops having been removed. Now, in supporting the ability for tsm_unregister() to always succeed, it leaves the problem of what to do with lingering config-items. The expectation is that the admin that arranges for the ->remove() (unbind) of the ${tsm_arch}-guest driver is also responsible for deletion of all open config-items. Until that deletion happens, ->probe() (reload / bind) of the ${tsm_arch}-guest driver fails. This allows for emergency shutdown / revocation of attestation interfaces, and requires coordinated restart.

Reserved 2025-04-16 | Published 2025-07-04 | Updated 2025-07-04 | Assigner Linux

Product status

Default status
unaffected

70e6f7e2b98575621019aa40ac616be58ff984e0 before 015f04ac884a454d4d8aaa7b67758f047742b1cf
affected

70e6f7e2b98575621019aa40ac616be58ff984e0 before cefbafcbdef011d6ef9414902311afdfba3c33eb
affected

70e6f7e2b98575621019aa40ac616be58ff984e0 before fba4ceaa242d2bdf4c04b77bda41d32d02d3925d
affected

Default status
affected

6.7
affected

Any version before 6.7
unaffected

6.12.35
unaffected

6.15.4
unaffected

6.16-rc1
unaffected

References

git.kernel.org/...c/015f04ac884a454d4d8aaa7b67758f047742b1cf

git.kernel.org/...c/cefbafcbdef011d6ef9414902311afdfba3c33eb

git.kernel.org/...c/fba4ceaa242d2bdf4c04b77bda41d32d02d3925d

cve.org (CVE-2025-38210)

nvd.nist.gov (CVE-2025-38210)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-38210

Support options

Helpdesk Chat, Email, Knowledgebase