-
CVE-2025-38688
- EPSS 0.03%
- Published 04.09.2025 15:32:42
- Last modified 05.09.2025 17:47:24
- Source 416baaa9-dc9f-4396-8d5f-8c081f
- Teams watchlist Login
- Open Login
In the Linux kernel, the following vulnerability has been resolved: iommufd: Prevent ALIGN() overflow When allocating IOVA the candidate range gets aligned to the target alignment. If the range is close to ULONG_MAX then the ALIGN() can wrap resulting in a corrupted iova. Open code the ALIGN() using get_add_overflow() to prevent this. This simplifies the checks as we don't need to check for length earlier either. Consolidate the two copies of this code under a single helper. This bug would allow userspace to create a mapping that overlaps with some other mapping or a reserved range.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
≫
Product
Linux
Default Statusunaffected
Version <
d19b817540c0abe84854a64ee9ee34cecc3bbeef
Version
51fe6141f0f64ae0bbc096a41a07572273e8c0ef
Status
affected
Version <
ebb6021560b94649bec6b8faba6fe0dca2218e81
Version
51fe6141f0f64ae0bbc096a41a07572273e8c0ef
Status
affected
Version <
e42a046bb41dcdde4f766a17d8211842007ed537
Version
51fe6141f0f64ae0bbc096a41a07572273e8c0ef
Status
affected
Version <
79fad1917802c28de51a479318a056a6fbe3e2f2
Version
51fe6141f0f64ae0bbc096a41a07572273e8c0ef
Status
affected
Version <
b42497e3c0e74db061eafad41c0cd7243c46436b
Version
51fe6141f0f64ae0bbc096a41a07572273e8c0ef
Status
affected
VendorLinux
≫
Product
Linux
Default Statusaffected
Version
6.2
Status
affected
Version <
6.2
Version
0
Status
unaffected
Version <=
6.6.*
Version
6.6.103
Status
unaffected
Version <=
6.12.*
Version
6.12.43
Status
unaffected
Version <=
6.15.*
Version
6.15.11
Status
unaffected
Version <=
6.16.*
Version
6.16.2
Status
unaffected
Version <=
*
Version
6.17-rc1
Status
unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.057 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|