CVE-2025-38366 Information

Description

In the Linux kernel the following vulnerability has been resolved:

LoongArch: KVM: Check validity of um_cpu\ from user space

The maximum supported cpu number is EIOINTC_ROUTE_MAX_VCPUS about irqchip EIOINTC here add validation about cpu number to avoid array pointer overflow.

Reference

https://git.kernel.org/stable/c/a3293b4078ee93174f70f36d3ab7618554ce6ab6 https://git.kernel.org/stable/c/cc8d5b209e09d3b52bca1ffe00045876842d96ae

CNNVD-202507-3192 (Published: 2025-07-25)

Share on: