« Volver al listado

CVE-2025-38093

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

arm64: dts: qcom: x1e80100: Add GPU cooling

Unlike the CPU, the GPU does not throttle its speed automatically when it reaches high temperatures. With certain high GPU loads it is possible to reach the critical hardware shutdown temperature of 120°C, endangering the hardware and making it impossible to run certain applications.

Set up GPU cooling similar to the ACPI tables, by throttling the GPU speed when reaching 95°C and polling every 200ms.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-38093",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "721e38301b79a6ee8375cb0ebd586699a7f353e3",
              "lessThan": "cd9d354bdd28b20a8f3170dab3bc0f096e66d6b4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "721e38301b79a6ee8375cb0ebd586699a7f353e3",
              "lessThan": "ae664ca09072857349857530dce12e09c048b12d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "721e38301b79a6ee8375cb0ebd586699a7f353e3",
              "lessThan": "d145a6a3e252f093dc243d2944fecb2387a3d690",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "721e38301b79a6ee8375cb0ebd586699a7f353e3",
              "lessThan": "5ba21fa11f473c9827f378ace8c9f983de9e0287",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm64/boot/dts/qcom/x1e80100.dtsi"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.34",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.14.10",
              "versionType": "semver",
              "lessThanOrEqual": "6.14.*"
            },
            {
              "status": "unaffected",
              "version": "6.15.1",
              "versionType": "semver",
              "lessThanOrEqual": "6.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.16",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm64/boot/dts/qcom/x1e80100.dtsi"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-07-02T15:15:26.317",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5ba21fa11f473c9827f378ace8c9f983de9e0287",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ae664ca09072857349857530dce12e09c048b12d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cd9d354bdd28b20a8f3170dab3bc0f096e66d6b4",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d145a6a3e252f093dc243d2944fecb2387a3d690",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: dts: qcom: x1e80100: Add GPU cooling\n\nUnlike the CPU, the GPU does not throttle its speed automatically when it\nreaches high temperatures. With certain high GPU loads it is possible to\nreach the critical hardware shutdown temperature of 120°C, endangering the\nhardware and making it impossible to run certain applications.\n\nSet up GPU cooling similar to the ACPI tables, by throttling the GPU speed\nwhen reaching 95°C and polling every 200ms."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: arm64: dts: qcom: x1e80100: Añadir refrigeración de la GPU. A diferencia de la CPU, la GPU no reduce su velocidad automáticamente al alcanzar altas temperaturas. Con ciertas cargas altas de la GPU, es posible alcanzar la temperatura crítica de apagado del hardware de 120 °C, lo que pone en peligro el hardware e imposibilita la ejecución de ciertas aplicaciones. Configure la refrigeración de la GPU de forma similar a las tablas ACPI, limitando la velocidad de la GPU al alcanzar los 95 °C y realizando un sondeo cada 200 ms."
    }
  ],
  "lastModified": "2026-06-17T09:16:02.430",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51F754D9-F4F7-4E6E-BFD8-0BC3B2C2D498",
              "versionEndExcluding": "6.12.34",
              "versionStartIncluding": "6.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB4249FA-EF24-4488-A579-B8E8EE87EA6F",
              "versionEndExcluding": "6.14.10",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACD734B1-0431-4BEB-9769-ECB016833EB2",
              "versionEndExcluding": "6.15.1",
              "versionStartIncluding": "6.15"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}