cbcvebase.
CVE-2025-38077
published 2025-06-18

CVE-2025-38077: In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Avoid buffer overflow in current_password_store() If the…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Avoid buffer overflow in current_password_store() If the 'buf' array received from the user contains an empty string, the 'length' variable will be zero. Accessing the 'buf' array element with index 'length - 1' will result in a buffer overflow. Add a check for an empty string. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < fb7cde625872709b8cedad9b241e0ec3d82fa7d3fb7cde625872709b8cedad9b241e0ec3d82fa7d3
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < 60bd13f8c4b3de2c910ae1cdbef85b9bbc9685f560bd13f8c4b3de2c910ae1cdbef85b9bbc9685f5
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < f86465626917df3b8bdd2756ec0cc9d179c5af0ff86465626917df3b8bdd2756ec0cc9d179c5af0f
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < 8594a123cfa23d708582dc6fb36da34479ef8a5b8594a123cfa23d708582dc6fb36da34479ef8a5b
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < 97066373ffd55bd9af0b512ff3dd1f647620a3dc97066373ffd55bd9af0b512ff3dd1f647620a3dc
linuxlinux>= e8a60aa7404bfef37705da5607c97737073ac38d < 4e89a4077490f52cde652d17e32519b666abf3a64e89a4077490f52cde652d17e32519b666abf3a6
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 5.15.0-152.1625.15.0-152.162
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.11 < 5.15.1855.15.185
linuxlinux_kernel>= 5.16 < 6.1.1416.1.141
linuxlinux_kernel>= 6.13 < 6.14.96.14.9
linuxlinux_kernel>= 6.2 < 6.6.936.6.93
linuxlinux_kernel>= 6.7 < 6.12.316.12.31
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH