Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Don't treat wb connector as physical in create_validate_stream_for_sink Don't try to operate on a drm_wb_connector as an amdgpu_dm_connector. While dereferencing aconnector->base will "work" it's wrong and might lead to unknown bad things. Just... don't.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.7.2, < 6.12.31 |
References
- https://git.kernel.org/stable/c/18ca68f7c657721583a75cab01f0d0d2ec63a6c9Patch
- https://git.kernel.org/stable/c/b14e726d57f61085485f107a6203c50a09695abdPatch
- https://git.kernel.org/stable/c/cbf4890c6f28fb1ad733e14613fbd33c2004bcedPatch
FAQ
What is CVE-2025-38098?
CVE-2025-38098 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Don't treat wb connector as physical in create_validate_stream_for_sink Don't try to operate on a drm_wb_connecto...
How severe is CVE-2025-38098?
CVE-2025-38098 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-38098?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.