CVE-2025-38433 | Linux Kernel up to 6.15.4/6.16-rc3 riscv __runtime_fixup_32 addi_insn_mask random values (WID-SEC-2025-1653)
A vulnerability was found in Linux Kernel up to 6.15.4/6.16-rc3. It has been classified as problematic. Impacted is the function __runtime_fixup_32 of the component riscv. This manipulation of the argument addi_insn_mask causes insufficiently random values.
This vulnerability is tracked as CVE-2025-38433. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is recommended.