CVE-2025-38088

In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mmap issue has an out of bounds issue. This patch fixes the by checking that the requested mapping region size should stay within the allocated region size.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

17 Dec 2025, 18:13

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/620b77b23c41a6546e5548ffe2ea3ad71880dde4 - () https://git.kernel.org/stable/c/620b77b23c41a6546e5548ffe2ea3ad71880dde4 - Patch
References () https://git.kernel.org/stable/c/81260c41b518b6f32c701425f1427562fa92f293 - () https://git.kernel.org/stable/c/81260c41b518b6f32c701425f1427562fa92f293 - Patch
References () https://git.kernel.org/stable/c/8635e325b85dfb9ddebdfaa6b5605d40d16cd147 - () https://git.kernel.org/stable/c/8635e325b85dfb9ddebdfaa6b5605d40d16cd147 - Patch
References () https://git.kernel.org/stable/c/9c340b56d60545e4a159e41523dd8b23f81d3261 - () https://git.kernel.org/stable/c/9c340b56d60545e4a159e41523dd8b23f81d3261 - Patch
References () https://git.kernel.org/stable/c/bbd5a9ddb0f9750783a48a871c9e12c0b68c5f39 - () https://git.kernel.org/stable/c/bbd5a9ddb0f9750783a48a871c9e12c0b68c5f39 - Patch
References () https://git.kernel.org/stable/c/cd097df4596f3a1e9d75eb8520162de1eb8485b2 - () https://git.kernel.org/stable/c/cd097df4596f3a1e9d75eb8520162de1eb8485b2 - Patch
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory
CWE CWE-125
First Time Linux
Debian
Debian debian Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

03 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html -

30 Jun 2025, 18:38

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: powerpc/powernv/memtrace: Se solucionó un problema de sobreexceso de los límites en memtrace mmap. Este parche corrige este problema comprobando que el tamaño de la región de mapeo solicitada se mantenga dentro del tamaño de la región asignada.

30 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-30 08:15

Updated : 2025-12-17 18:13


NVD link : CVE-2025-38088

Mitre link : CVE-2025-38088

CVE.ORG link : CVE-2025-38088


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read