目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-38395— Linux kernel 安全漏洞

CVSS 8.4 · High EPSS 0.17% · P7

可能的 ATT&CK 技术 1AI

T1135 · Network Share Discovery

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinuxd6cd33ad71029a3f77ba1686caf55d4dea58d916< a3cd5ae7befbac849e0e0529c94ca04e8093cfd2affected
d6cd33ad71029a3f77ba1686caf55d4dea58d916< 9fe71972869faed1f8f9b3beb9040f9c1b300c79affected
d6cd33ad71029a3f77ba1686caf55d4dea58d916< 56738cbac3bbb1d39a71a07f57484dec1db8b239affected
d6cd33ad71029a3f77ba1686caf55d4dea58d916< a1e12fac214d4f49fcb186dbdf9c5592e7fa0a7aaffected
d6cd33ad71029a3f77ba1686caf55d4dea58d916< 24418bc77a66cb5be9f5a837431ba3674ed8b52faffected
d6cd33ad71029a3f77ba1686caf55d4dea58d916< e4d19e5d71b217940e33f2ef6c6962b7b68c5606affected
d6cd33ad71029a3f77ba1686caf55d4dea58d916< 3830ab97cda9599872625cc0dc7b00160193634faffected
d6cd33ad71029a3f77ba1686caf55d4dea58d916< c9764fd88bc744592b0604ccb6b6fc1a5f76b4e3affected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-38395 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods drvdata::gpiods is supposed to hold an array of 'gpio_desc' pointers. But the memory is allocated for only one pointer. This will lead to out-of-bounds access later in the code if 'config::ngpios' is > 1. So fix the code to allocate enough memory to hold 'config::ngpios' of GPIO descriptors. While at it, also move the check for memory allocation failure to be below the allocation to make it more readable.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于gpiods数组分配不足可能导致越界访问。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux d6cd33ad71029a3f77ba1686caf55d4dea58d916 ~ a3cd5ae7befbac849e0e0529c94ca04e8093cfd2 -
LinuxLinux 5.1 -

二、漏洞 CVE-2025-38395 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-38395 的情报信息

登录查看更多情报信息。

同批安全公告 · Linux · 2025-07-25 · 共 114 条

CVE-2025-3842910.0 CRITICALLinux kernel 安全漏洞
CVE-2025-384119.8 CRITICALLinux kernel 安全漏洞
CVE-2025-384309.8 CRITICALLinux kernel 安全漏洞
CVE-2025-384399.8 CRITICALLinux kernel 安全漏洞
CVE-2025-383659.1 CRITICALLinux kernel 安全漏洞
CVE-2025-384378.8 HIGHLinux kernel 安全漏洞
CVE-2025-383778.8 HIGHLinux kernel 安全漏洞
CVE-2025-383678.8 HIGHLinux kernel 安全漏洞
CVE-2025-383758.4 HIGHLinux kernel 安全漏洞
CVE-2025-383867.8 HIGHLinux kernel 安全漏洞
CVE-2025-384347.8 HIGHLinux kernel 安全漏洞
CVE-2025-384497.8 HIGHLinux kernel 安全漏洞
CVE-2025-383827.8 HIGHLinux kernel 安全漏洞
CVE-2025-384127.8 HIGHLinux kernel 安全漏洞
CVE-2025-384477.8 HIGHLinux kernel 安全漏洞
CVE-2025-384017.8 HIGHLinux kernel 安全漏洞
CVE-2025-383967.8 HIGHLinux kernel 安全漏洞
CVE-2025-384407.8 HIGHLinux kernel 安全漏洞
CVE-2025-384087.8 HIGHLinux kernel 安全漏洞
CVE-2025-383987.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 114 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38395

暂无评论


发表评论