# CVE-2025-38704

## Summary

- **CVE ID:** CVE-2025-38704
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 4, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access

In the preparation stage of CPU online, if the corresponding
the rdp's->nocb_cb_kthread does not exist, will be created,
there is a situation where the rdp's rcuop kthreads creation fails,
and then de-offload this CPU's rdp, does not assign this CPU's
rdp->nocb_cb_kthread pointer, but this rdp's->nocb_gp_rdp and
rdp's->rdp_gp->nocb_gp_kthread is still valid.

This will cause the subsequent re-offload operation of this offline
CPU, which will pass the conditional check and the kthread_unpark()
will access invalid rdp's->nocb_cb_kthread pointer.

This commit therefore use rdp's->nocb_gp_kthread instead of
rdp_gp's->nocb_gp_kthread for safety check.

## Affected Products

- Linux — Linux (3a5761dc025da47960755ac64d9fbf1c32e8cd80)
- Linux — Linux (6.0)
- Linux — Linux (0)
- Linux — Linux (6.12.43)
- Linux — Linux (6.15.11)
- Linux — Linux (6.16.2)
- Linux — Linux (6.17)
- Linux — Linux (6.1.167)
- Linux — Linux (6.6.130)

## References

- [CNA](https://git.kernel.org/stable/c/cce3d027227c69e85896af9fbc6fa9af5c68f067)
- [CNA](https://git.kernel.org/stable/c/1c951683a720b17c9ecaad1932bc95b29044611f)
- [CNA](https://git.kernel.org/stable/c/9b5ec8e6b31755288a07b3abeeab8cd38e9d3c9d)
- [CNA](https://git.kernel.org/stable/c/1bba3900ca18bdae28d1b9fa10f16a8f8cb2ada1)
- [CNA](https://git.kernel.org/stable/c/b097ae798298885695c339d390b48b4e39619fa7)
- [CNA](https://git.kernel.org/stable/c/3da45ec1e485a1a5ad31fe9ddd467c7ee5ae4ef9)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-082556.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._