CVE-2025-38077 — Out-of-bounds Write in Linux
Severity
7.8HIGHNVD
OSV5.5OSV3.2
EPSS
0.1%
top 78.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 18
Latest updateMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: dell-wmi-sysman: Avoid buffer overflow in current_password_store()
If the 'buf' array received from the user contains an empty string, the
'length' variable will be zero. Accessing the 'buf' array element with
index 'length - 1' will result in a buffer overflow.
Add a check for an empty string.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages4 packages
▶CVEListV5linux/linuxe8a60aa7404bfef37705da5607c97737073ac38d — fb7cde625872709b8cedad9b241e0ec3d82fa7d3+6
Also affects: Debian Linux 11.0