CVE-2025-38004 — Out-of-bounds Read in Linux
Severity
7.1HIGHNVD
OSV5.5OSV3.2
EPSS
0.1%
top 74.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: add locking for bcm_op runtime updates
The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via
hrtimer. The content and also the length of the sequence can be changed
resp reduced at runtime where the 'currframe' counter is then set to zero.
Although this appeared to be a safe operation the updates of 'currframe'
can be triggered from user space and hrtimer context in bcm_can_tx().
Anderson Nascime…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2
Affected Packages4 packages
▶CVEListV5linux/linuxffd980f976e7fd666c2e61bf8ab35107efd11828 — 8f1c022541bf5a923c8d6fa483112c15250f30a4+8
Also affects: Debian Linux 11.0