cbcvebase.
CVE-2025-38082
published 2025-06-18

CVE-2025-38082: In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix potential out-of-bound write If the caller wrote more characters, count…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.3th percentile
In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix potential out-of-bound write If the caller wrote more characters, count is truncated to the max available space in "simple_write_to_buffer". Check that the input size does not exceed the buffer size. Write a zero termination afterwards.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.32-1 (forky)linux 6.12.32-1 (forky)
linuxlinux
linuxlinux>= 91581c4b3f29e2e22aeb1a62e842d529ca638b2d < afe090366f470f77e140ff3407db813f57852c04afe090366f470f77e140ff3407db813f57852c04
linuxlinux>= 91581c4b3f29e2e22aeb1a62e842d529ca638b2d < b96feaaa0fda1e3871b438143c3446954b32d3a7b96feaaa0fda1e3871b438143c3446954b32d3a7
linuxlinux>= 91581c4b3f29e2e22aeb1a62e842d529ca638b2d < 7118be7c6072f40391923543fdd1563b8d56377c7118be7c6072f40391923543fdd1563b8d56377c
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 6.11 < 6.12.326.12.32
linuxlinux_kernel>= 6.13 < 6.14.106.14.10
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.