Security readout for executives and security teams
Plain-English summary
A flaw in the Linux AMD GPU driver can access memory after it has been freed during GPU removal or driver shutdown. A local, low-privileged user may be able to crash the system or potentially affect confidentiality and integrity. Exposure depends on running the affected kernel code with the AMDGPU driver.
Executive priority
Treat as a high-priority kernel maintenance issue for AMD GPU fleets, especially shared workstations, compute hosts, and systems allowing untrusted local workloads. It is less urgent for systems without AMDGPU exposure. There is no supplied evidence of active exploitation, so prioritize through normal accelerated patching rather than emergency incident response.
Technical view
The vulnerability is a slab use-after-free in amdgpu_userq_suspend during AMDGPU device teardown. KASAN observed an eight-byte read after amdgpu_userq_mgr had been freed while processing PCI device removal. The supplied CVSS 3.1 rating is 7.8, requiring local access and low privileges, without user interaction.
Likely exposure
Likely exposure is limited to Linux systems using AMD GPUs and the amdgpu driver on an affected kernel. The supplied version data identifies Linux 6.16 and additional 6.16.1/6.17 boundary entries, but its flattened format is ambiguous. Confirm distribution-specific package status and fix backports.
Exploitation context
No active exploitation is established: the supplied record is not in KEV and provides no cited evidence of attacks. The demonstrated failure occurred during privileged PCI GPU unplug or driver teardown. Although CVSS models a local, low-privileged attacker, the bundle does not explain a reliable attacker-controlled trigger or exploitation method.
Researcher notes
The evidence establishes an eight-byte slab use-after-free read in amdgpu_userq_suspend during PCI removal. CVSS claims possible confidentiality, integrity, and availability impact, but the bundle supplies no exploit analysis demonstrating those outcomes. No CWE is assigned, no CPEs are provided, and affected-version boundaries require vendor confirmation.
Mitigation direction
Install a vendor-supported kernel containing the applicable stable fix referenced by the CVE record.
Prioritize AMD GPU systems where untrusted local users or workloads can access GPU functionality.
If immediate patching is unavailable, consult the Linux distribution vendor for supported mitigations.
Restrict unnecessary local access and GPU device access until affected systems are remediated.
Validation and detection
Inventory Linux kernel versions and identify systems loading the amdgpu driver.
Check distribution advisories or package metadata for a backport of the referenced fix.
Confirm the running kernel contains an applicable listed stable commit or vendor-equivalent patch.
After updating, reboot into the corrected kernel and verify the previous kernel is not active.
Monitor kernel logs for KASAN, use-after-free, amdgpu teardown, or unexpected GPU-related crashes.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-38598 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
3Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.