-
CVE-2025-38342
- EPSS 0.04%
- Published 10.07.2025 08:15:11
- Last modified 10.07.2025 13:17:30
- Source 416baaa9-dc9f-4396-8d5f-8c081f
- Teams watchlist Login
- Open Login
In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args() software_node_get_reference_args() wants to get @index-th element, so the property value requires at least '(index + 1) * sizeof(*ref)' bytes but that can not be guaranteed by current OOB check, and may cause OOB for malformed property. Fix by using as OOB check '((index + 1) * sizeof(*ref) > prop->length)'.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
≫
Product
Linux
Default Statusunaffected
Version <
142acd739eb6f08c148a96ae8309256f1422ff4b
Version
59abd83672f70cac4b6bf9b237506c5bc6837606
Status
affected
Version <
56ce76e8d406cc72b89aee7931df5cf3f18db49d
Version
59abd83672f70cac4b6bf9b237506c5bc6837606
Status
affected
Version <
9324127b07dde8529222dc19233aa57ec810856c
Version
59abd83672f70cac4b6bf9b237506c5bc6837606
Status
affected
Version <
f9397cf7bfb680799fb8c7f717c8f756384c3280
Version
59abd83672f70cac4b6bf9b237506c5bc6837606
Status
affected
Version <
4b3383110b6df48e0ba5936af2cb68d5eb6bd43b
Version
59abd83672f70cac4b6bf9b237506c5bc6837606
Status
affected
Version <
7af18e42bdefe1dba5bcb32555a4d524fd504939
Version
59abd83672f70cac4b6bf9b237506c5bc6837606
Status
affected
Version <
31e4e12e0e9609850cefd4b2e1adf782f56337d6
Version
59abd83672f70cac4b6bf9b237506c5bc6837606
Status
affected
VendorLinux
≫
Product
Linux
Default Statusaffected
Version
5.0
Status
affected
Version <
5.0
Version
0
Status
unaffected
Version <=
5.10.*
Version
5.10.239
Status
unaffected
Version <=
5.15.*
Version
5.15.186
Status
unaffected
Version <=
6.1.*
Version
6.1.142
Status
unaffected
Version <=
6.6.*
Version
6.6.95
Status
unaffected
Version <=
6.12.*
Version
6.12.35
Status
unaffected
Version <=
6.15.*
Version
6.15.4
Status
unaffected
Version <=
*
Version
6.16
Status
unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.098 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|