CNNVD-202508-936 Information

CNNVD ID

CNNVD-202508-936

CVE-2025-38499

  • CNNVD Published: 2025-08-11

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于clone_private_mnt未验证用户命名空间中的CAP_SYS_ADMIN权限,可能导致权限提升。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. Linux Kernel has a security loophole, which stems from the failure to verify CAP SYS ADMIN privileges in the user namespace, which may lead to an increase in privileges.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Linux

Published

2025-08-11

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/c28f922c9dcee0e4876a2c095939d77fe7e15116 https://git.kernel.org/stable/c/38628ae06e2a37770cd794802a3f1310cf9846e3 https://git.kernel.org/stable/c/dc6a664089f10eab0fb36b6e4f705022210191d2 https://git.kernel.org/stable/c/e77078e52fbf018ab986efb3c79065ab35025607 https://git.kernel.org/stable/c/d717325b5ecf2a40daca85c61923e17f32306179 https://git.kernel.org/stable/c/36fecd740de2d542d2091d65d36554ee2bcf9c65 https://nvd.nist.gov/vuln/detail/CVE-2025-38499

Patch

https://www.kernel.org/

Share on: