In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Configurations
History
08 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-20 |
08 Dec 2025, 19:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* | |
| First Time |
Google android
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| References | () https://android.googlesource.com/kernel/common/+/0429b7af308cf65c84109c08d06b01950dcd57fe - Product | |
| References | () https://android.googlesource.com/kernel/common/+/96ebe96170d67df5072afa2ce84622f5a0ff552a - Product | |
| References | () https://source.android.com/security/bulletin/2025-12-01 - Vendor Advisory | |
| CWE | CWE-787 |
08 Dec 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-08 17:16
Updated : 2025-12-08 20:15
NVD link : CVE-2025-48638
Mitre link : CVE-2025-48638
CVE.ORG link : CVE-2025-48638
JSON object : View
Products Affected
- android
