cbcvebase.
CVE-2025-39815
published 2025-09-16

CVE-2025-39815: In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb The userspace load can put up to 2048…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.0th percentile
In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb The userspace load can put up to 2048 bits into an xlen bit stack buffer. We want only xlen bits, so check the size beforehand.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.5-1 (forky)linux 6.16.5-1 (forky)
linuxlinux
linuxlinux>= 2fa290372dfe7dd248b1c16f943f273a3e674f22 < c76bf8359188a11f8fd790e5bbd6077894a245ccc76bf8359188a11f8fd790e5bbd6077894a245cc
linuxlinux>= 2fa290372dfe7dd248b1c16f943f273a3e674f22 < 6d28659b692a0212f360f8bd8a58712b339f9aac6d28659b692a0212f360f8bd8a58712b339f9aac
linuxlinux>= 2fa290372dfe7dd248b1c16f943f273a3e674f22 < 799766208f09f95677a9ab111b93872d414fbad7799766208f09f95677a9ab111b93872d414fbad7
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.5-16.16.5-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.13 < 6.16.56.16.5
linuxlinux_kernel>= 6.8 < 6.12.456.12.45
ubuntulinux-xilinx

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.