CVE-2025-38088

high

Description

In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mmap issue has an out of bounds issue. This patch fixes the by checking that the requested mapping region size should stay within the allocated region size.

References

https://git.kernel.org/stable/c/cd097df4596f3a1e9d75eb8520162de1eb8485b2

https://git.kernel.org/stable/c/bbd5a9ddb0f9750783a48a871c9e12c0b68c5f39

https://git.kernel.org/stable/c/9c340b56d60545e4a159e41523dd8b23f81d3261

https://git.kernel.org/stable/c/8635e325b85dfb9ddebdfaa6b5605d40d16cd147

https://git.kernel.org/stable/c/81260c41b518b6f32c701425f1427562fa92f293

https://git.kernel.org/stable/c/620b77b23c41a6546e5548ffe2ea3ad71880dde4

Details

Source: Mitre, NVD

Published: 2025-06-30

Updated: 2025-06-30

Risk Information

CVSS v2

Base Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:P

Severity: Low

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00024