CVE-2025-48610
published 2025-12-08CVE-2025-48610: In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in the code. This could lead to local…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.08%
0.3th percentile
In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h29f-7h38-wrgx: In __pkvm_guest_relinquish_to_host of mem_protect
ghsa_unreviewed·2025-12-08
CVE-2025-48610 [MEDIUM] GHSA-h29f-7h38-wrgx: In __pkvm_guest_relinquish_to_host of mem_protect
In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2025-48610: In __pkvm_guest_relinquish_to_host of mem_protect
osv·2025-12-01
CVE-2025-48610 CVE-2025-48610: In __pkvm_guest_relinquish_to_host of mem_protect
In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2025-48610: Kernel Virtual Machine
vendor_android·2025-12-01·CVSS 5.5
CVE-2025-48610 [MEDIUM] CVE-2025-48610: Kernel Virtual Machine
Android Security Bulletin 2025-12-01
CVE: CVE-2025-48610
Severity: HIGH
Type: ID
Component: Kernel Virtual Machine
References: A-432439762Upstream kernel
[2]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-08
Published