CNNVD-202508-2763 Information

CNNVD ID

CNNVD-202508-2763

CVE-2025-38653

  • CNNVD Published: 2025-08-22

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于proc在检查proc_lseek时与proc_read_iter等处理方式不一致,可能导致UAF。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. Linux Kernel had a security loophole, which stemmed from a lack of consistency between proc leseek and proc read iter, among others, which could lead to UAF.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Linux

Published

2025-08-22

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/ff7ec8dc1b646296f8d94c39339e8d3833d16c05 https://git.kernel.org/stable/c/fc1072d934f687e1221d685cf1a49a5068318f34 https://git.kernel.org/stable/c/d136502e04d8853a9aecb335d07bbefd7a1519a8 https://git.kernel.org/stable/c/c35b0feb80b48720dfbbf4e33759c7be3faaebb6 https://git.kernel.org/stable/c/33c778ea0bd0fa62ff590497e72562ff90f82b13 https://git.kernel.org/stable/c/1fccbfbae1dd36198dc47feac696563244ad81d3 https://nvd.nist.gov/vuln/detail/CVE-2025-38653 https://access.redhat.com/security/cve/cve-2025-38653

Patch

https://www.kernel.org/

Share on: