cbcvebase.
CVE-2025-38068
published 2025-06-18

CVE-2025-38068: In the Linux kernel, the following vulnerability has been resolved: crypto: lzo - Fix compression buffer overrun Unlike the decompression code, the compression…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved: crypto: lzo - Fix compression buffer overrun Unlike the decompression code, the compression code in LZO never checked for output overruns. It instead assumes that the caller always provides enough buffer space, disregarding the buffer length provided by the caller. Add a safe compression interface that checks for the end of buffer before each write. Use the safe interface in crypto/lzo.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= 64c70b1cf43de158282bc1675918d503e5b15cc1 < 4b173bb2c4665c23f8fcf5241c7b06dfa6b5b1114b173bb2c4665c23f8fcf5241c7b06dfa6b5b111
linuxlinux>= 64c70b1cf43de158282bc1675918d503e5b15cc1 < a98bd864e16f91c70b2469adf013d713d04d1d13a98bd864e16f91c70b2469adf013d713d04d1d13
linuxlinux>= 64c70b1cf43de158282bc1675918d503e5b15cc1 < 0acdc4d6e679ba31d01e3e7e2e4124b76d6d8e2a0acdc4d6e679ba31d01e3e7e2e4124b76d6d8e2a
linuxlinux>= 64c70b1cf43de158282bc1675918d503e5b15cc1 < 7caad075acb634a74911830d6386c50ea12566cd7caad075acb634a74911830d6386c50ea12566cd
linuxlinux>= 64c70b1cf43de158282bc1675918d503e5b15cc1 < 167373d77c70c2b558aae3e327b115249bb2652c167373d77c70c2b558aae3e327b115249bb2652c
linuxlinux>= 64c70b1cf43de158282bc1675918d503e5b15cc1 < cc47f07234f72cbd8e2c973cdbf2a6730660a463cc47f07234f72cbd8e2c973cdbf2a6730660a463
linuxlinux_kernel< 5.15.1855.15.185
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 5.15.0-152.1625.15.0-152.162
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.16 < 6.1.1416.1.141
linuxlinux_kernel>= 6.13 < 6.14.96.14.9
linuxlinux_kernel>= 6.2 < 6.6.936.6.93
linuxlinux_kernel>= 6.7 < 6.12.316.12.31
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.1-1_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH