-

CVE-2025-38639

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_nfacct: don't assume acct name is null-terminated

BUG: KASAN: slab-out-of-bounds in .. lib/vsprintf.c:721
Read of size 1 at addr ffff88801eac95c8 by task syz-executor183/5851
[..]
 string+0x231/0x2b0 lib/vsprintf.c:721
 vsnprintf+0x739/0xf00 lib/vsprintf.c:2874
 [..]
 nfacct_mt_checkentry+0xd2/0xe0 net/netfilter/xt_nfacct.c:41
 xt_check_match+0x3d1/0xab0 net/netfilter/x_tables.c:523

nfnl_acct_find_get() handles non-null input, but the error
printk relied on its presence.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 66d41268ede1e1b6e71ba28be923397ff0b2b9c3
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
Version < e021a1eee196887536a6630c5492c23a4c78d452
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
Version < b10cfa2de13d28ddd03210eb234422b7ec92725a
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
Version < e18939176e657a3a20bfbed357b8c55a9f82aba3
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
Version < 58004aa21e79addaf41667bfe65e93ec51653f18
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
Version < 7c1ae471da69c09242834e956218ea6a42dd405a
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
Version < 58007fc7b94fb2702000045ff401eb7f5bde7828
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
Version < df13c9c6ce1d55c31d1bd49db65a7fbbd86aab13
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
Version < bf58e667af7d96c8eb9411f926a0a0955f41ce21
Version ceb98d03eac5704820f2ac1f370c9ff385e3a9f5
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.3
Status affected
Version < 3.3
Version 0
Status unaffected
Version <= 5.4.*
Version 5.4.297
Status unaffected
Version <= 5.10.*
Version 5.10.241
Status unaffected
Version <= 5.15.*
Version 5.15.190
Status unaffected
Version <= 6.1.*
Version 6.1.148
Status unaffected
Version <= 6.6.*
Version 6.6.102
Status unaffected
Version <= 6.12.*
Version 6.12.42
Status unaffected
Version <= 6.15.*
Version 6.15.10
Status unaffected
Version <= 6.16.*
Version 6.16.1
Status unaffected
Version <= *
Version 6.17-rc1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.142
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String