-

CVE-2025-38277

In the Linux kernel, the following vulnerability has been resolved:

mtd: nand: ecc-mxic: Fix use of uninitialized variable ret

If ctx->steps is zero, the loop processing ECC steps is skipped,
and the variable ret remains uninitialized. It is later checked
and returned, which leads to undefined behavior and may cause
unpredictable results in user space or kernel crashes.

This scenario can be triggered in edge cases such as misconfigured
geometry, ECC engine misuse, or if ctx->steps is not validated
after initialization.

Initialize ret to zero before the loop to ensure correct and safe
behavior regardless of the ctx->steps value.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 4d9d6e4be09472aa72953caca3dbefdc27846170
Version 48e6633a9fa2400b53a964358753769f291a7eb0
Status affected
Version < a0d9d9b5a4634e146ae41cb25667322e5c7d74d2
Version 48e6633a9fa2400b53a964358753769f291a7eb0
Status affected
Version < 7a23cc510ecaabab4f6df7e9d910d16e279b72ad
Version 48e6633a9fa2400b53a964358753769f291a7eb0
Status affected
Version < 49482f4a39620f6afedcd3f6aa9e0d558b6a460b
Version 48e6633a9fa2400b53a964358753769f291a7eb0
Status affected
Version < d95846350aac72303036a70c4cdc69ae314aa26d
Version 48e6633a9fa2400b53a964358753769f291a7eb0
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.18
Status affected
Version < 5.18
Version 0
Status unaffected
Version <= 6.1.*
Version 6.1.142
Status unaffected
Version <= 6.6.*
Version 6.6.94
Status unaffected
Version <= 6.12.*
Version 6.12.34
Status unaffected
Version <= 6.15.*
Version 6.15.3
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.06
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string