CVE-2025-38484 Information
Jul 29, 2025
cve
Description
In the Linux kernel the following vulnerability has been resolved:
iio: backend: fix out-of-bound write
The buffer is set to 80 character. If a caller write more characters count is truncated to the max available space in \simple_write_to_buffer. But afterwards a string terminator is written to the buffer at offset count without boundary check. The zero termination is written OUT-OF-BOUND.
Add a check that the given buffer is smaller then the buffer to prevent.
Reference
https://git.kernel.org/stable/c/01e941aa7f5175125df4ac5d3aab099961525602 https://git.kernel.org/stable/c/6eea9f7648ddb9e4903735a1f77cf196c957aa38 https://git.kernel.org/stable/c/da9374819eb3885636934c1006d450c3cb1a02ed
Related CNNVD
CNNVD-202507-3507 (Published: 2025-07-28)
Share on: