CVE-2025-38182

In the Linux kernel, the following vulnerability has been resolved: ublk: santizize the arguments from userspace when adding a device Sanity check the values for queue depth and number of queues we get from userspace when adding a device.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*

History

19 Nov 2025, 21:00

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0f8df5d6f25ac17c52a8bc6418e60a3e63130550 - () https://git.kernel.org/stable/c/0f8df5d6f25ac17c52a8bc6418e60a3e63130550 - Patch
References () https://git.kernel.org/stable/c/3162d8235c8c4d585525cee8a59d1c180940a968 - () https://git.kernel.org/stable/c/3162d8235c8c4d585525cee8a59d1c180940a968 - Patch
References () https://git.kernel.org/stable/c/8c8472855884355caf3d8e0c50adf825f83454b2 - () https://git.kernel.org/stable/c/8c8472855884355caf3d8e0c50adf825f83454b2 - Patch
References () https://git.kernel.org/stable/c/e2b2b7cf6368580114851cb3932f2ad9fbf23386 - () https://git.kernel.org/stable/c/e2b2b7cf6368580114851cb3932f2ad9fbf23386 - Patch
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux
Linux linux Kernel

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ublk: depurar los argumentos del espacio de usuario al agregar un dispositivo. Verificar la solidez de los valores de profundidad de cola y número de colas que obtenemos del espacio de usuario al agregar un dispositivo.

04 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-04 14:15

Updated : 2025-11-19 21:00


NVD link : CVE-2025-38182

Mitre link : CVE-2025-38182

CVE.ORG link : CVE-2025-38182


JSON object : View

Products Affected

linux

  • linux_kernel