CVE-2025-52568

high

Description

NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory corruption, disk image corruption, denial of service, and potential code execution. These issues stem from unchecked memory operations, unsafe typecasting, and improper input validation. This issue has been patched in version 0.0.3.

References

https://github.com/nekernel-org/nekernel/security/advisories/GHSA-cmp2-5f6g-mw34

https://github.com/nekernel-org/nekernel/pull/36

https://github.com/nekernel-org/nekernel/pull/35

https://github.com/nekernel-org/nekernel/commit/6511afbf405c31513bc88ab06bca58218610a994

https://github.com/nekernel-org/nekernel/commit/6506875ad0ab210b82a5c4ce227bf851508de17d

Details

Source: Mitre, NVD

Published: 2025-06-24

Updated: 2025-06-24

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 8.4

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 8.8

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00065