5.5
CVE-2025-38469
- EPSS 0.15%
- Veröffentlicht 28.07.2025 11:21:30
- Zuletzt bearbeitet 19.11.2025 17:58:18
- Erkennungen
KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host for more than one event channel potr (nr_ports > 1). After the kmalloc_array(), the error paths need to go through the "out" label, but the call to kvm_read_guest_virt() does not. [Adjusted commit message. - Paolo]
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.2.1 < 6.6.100
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.40
Linux ≫ Linux Kernel Version >= 6.13 < 6.15.8
Linux ≫ Linux Kernel Version 6.2 Update -
Linux ≫ Linux Kernel Version 6.2 Update rc2
Linux ≫ Linux Kernel Version 6.2 Update rc3
Linux ≫ Linux Kernel Version 6.2 Update rc4
Linux ≫ Linux Kernel Version 6.2 Update rc5
Linux ≫ Linux Kernel Version 6.2 Update rc6
Linux ≫ Linux Kernel Version 6.2 Update rc7
Linux ≫ Linux Kernel Version 6.2 Update rc8
Linux ≫ Linux Kernel Version 6.16 Update rc1
Linux ≫ Linux Kernel Version 6.16 Update rc2
Linux ≫ Linux Kernel Version 6.16 Update rc3
Linux ≫ Linux Kernel Version 6.16 Update rc4
Linux ≫ Linux Kernel Version 6.16 Update rc5
Linux ≫ Linux Kernel Version 6.16 Update rc6
Linux ≫ Linux Kernel Version 6.16 Update rc7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.047 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
https://git.kernel.org/stable/c/3ee59c38ae7369ad1f7b846e05633ccf0d159fab
https://git.kernel.org/stable/c/fd627ac8a5cff4d45269f164b13ddddc0726f2cc
https://git.kernel.org/stable/c/061c553c66bc1638c280739999224c8000fd4602
https://git.kernel.org/stable/c/5a53249d149f48b558368c5338b9921b76a12f8c