CVE-2025-39815

high

Description

In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb The userspace load can put up to 2048 bits into an xlen bit stack buffer. We want only xlen bits, so check the size beforehand.

References

https://git.kernel.org/stable/c/c76bf8359188a11f8fd790e5bbd6077894a245cc

https://git.kernel.org/stable/c/799766208f09f95677a9ab111b93872d414fbad7

https://git.kernel.org/stable/c/6d28659b692a0212f360f8bd8a58712b339f9aac

Details

Source: Mitre, NVD

Published: 2025-09-16

Updated: 2025-09-18

Risk Information

CVSS v2

Base Score: 6.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00017