CVE-2025-38367Improper Validation of Array Index in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 91.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 25

Description

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Avoid overflow with array index The variable index is modified and reused as array index when modify register EIOINTC_ENABLE. There will be array index overflow problem.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDlinux/linux_kernel6.136.15.5+1
CVEListV5linux/linux3956a52bc05bd811082a3c9d2b423ee957e6fefc2cc84c4b0d70d42e291862ecc848890d18e1004a+2
debiandebian/linux

Patches

🔴Vulnerability Details

2
GHSA
GHSA-43rg-xghf-cjwh: In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Avoid overflow with array index The variable index is modified a2025-07-25
OSV
CVE-2025-38367: In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Avoid overflow with array index The variable index is modified and2025-07-25

📋Vendor Advisories

2
Red Hat
kernel: LoongArch: KVM: Avoid overflow with array index2025-07-25
Debian
CVE-2025-38367: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...2025
CVE-2025-38367 — Improper Validation of Array Index | cvebase