[SRU][N][PATCH 0/1] CVE-2025-38187

Cengiz Can cengiz.can at canonical.com
Thu Sep 10 20:02:19 UTC 2026


https://ubuntu.com/security/CVE-2025-38187

[ Impact ]

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()

The RPC container is released after being passed to r535_gsp_rpc_send().

When sending the initial fragment of a large RPC and passing the caller's RPC
container, the container will be freed prematurely. Subsequent attempts to send
remaining fragments will therefore result in a use-after-free.

Allocate a temporary RPC container for holding the initial fragment of a large
RPC when sending. Free the caller's container when all fragments are
successfully sent.

[ Rebase onto Blackwell changes. - Danilo ]

[ Fix ]

noble/linux: backported from 9802f0a63b64

[ Test Plan ]

Build and boot tested.

[ Where Problems Could Occur ]

A bad fix here would affect systems running the nouveau driver on NVIDIA GPUs
that boot via GSP-RM firmware (Turing and later generations), specifically the
path that sends large RPC messages to the GSP. A regression could manifest as
memory corruption, RPC failures, or GPU init problems on those machines.
Systems without an NVIDIA GPU, systems not using nouveau, and older nouveau
GPUs that do not use the GSP-RM boot path are not affected.

[ Other Info ]

Kybele flow-v11-25-ga27c0fa6. Reference: 97f12392/v1



More information about the kernel-team mailing list