CVE-2025-38088

I

n the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mmap issue has an out of bounds issue. This patch fixes the by checking that the requested mapping region size should stay within the allocated region size.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

17 Dec 2025, 18:13

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/620b77b23c41a6546e5548ffe2ea3ad71880dde4 - () https://git.kernel.org/stable/c/620b77b23c41a6546e5548ffe2ea3ad71880dde4 - Patch
References () https://git.kernel.org/stable/c/81260c41b518b6f32c701425f1427562fa92f293 - () https://git.kernel.org/stable/c/81260c41b518b6f32c701425f1427562fa92f293 - Patch
References () https://git.kernel.org/stable/c/8635e325b85dfb9ddebdfaa6b5605d40d16cd147 - () https://git.kernel.org/stable/c/8635e325b85dfb9ddebdfaa6b5605d40d16cd147 - Patch
References () https://git.kernel.org/stable/c/9c340b56d60545e4a159e41523dd8b23f81d3261 - () https://git.kernel.org/stable/c/9c340b56d60545e4a159e41523dd8b23f81d3261 - Patch
References () https://git.kernel.org/stable/c/bbd5a9ddb0f9750783a48a871c9e12c0b68c5f39 - () https://git.kernel.org/stable/c/bbd5a9ddb0f9750783a48a871c9e12c0b68c5f39 - Patch
References () https://git.kernel.org/stable/c/cd097df4596f3a1e9d75eb8520162de1eb8485b2 - () https://git.kernel.org/stable/c/cd097df4596f3a1e9d75eb8520162de1eb8485b2 - Patch
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
First Time Linux linux Kernel
Debian
Linux
Debian debian Linux
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

03 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html -

30 Jun 2025, 18:38

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: powerpc/powernv/memtrace: Se solucionó un problema de sobreexceso de los límites en memtrace mmap. Este parche corrige este problema comprobando que el tamaño de la región de mapeo solicitada se mantenga dentro del tamaño de la región asignada.

30 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-30 08:15

Updated : 2025-12-17 18:13


NVD link : CVE-2025-38088

Mitre link : CVE-2025-38088

CVE.ORG link : CVE-2025-38088


JSON object : View

CWE
CWE-125

Out-of-bounds Read