目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-38680— Linux kernel 安全漏洞

AI Predicted 5.3 Difficulty: Moderate EPSS 0.18% · P7

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 20

ベンダープロダクトVersion Rangeステータス
LinuxLinuxc0efd232929c2cd87238de2cccdaf4e845be5b0c< 9ad554217c9b945031c73df4e8176a475e2dea57affected
c0efd232929c2cd87238de2cccdaf4e845be5b0c< 1e269581b3aa5962fdc52757ab40da286168c087affected
c0efd232929c2cd87238de2cccdaf4e845be5b0c< 8343f3fe0b755925f83d60b05e92bf4396879758affected
c0efd232929c2cd87238de2cccdaf4e845be5b0c< ffdd82182953df643aa63d999b6f1653d0c93778affected
c0efd232929c2cd87238de2cccdaf4e845be5b0c< a97e062e4ff3dab84a2f1eb811e9eddc6699e2a9affected
c0efd232929c2cd87238de2cccdaf4e845be5b0c< cac702a439050df65272c49184aef7975fe3eff2affected
c0efd232929c2cd87238de2cccdaf4e845be5b0c< 424980d33b3f816485513e538610168b03fab9f1affected
c0efd232929c2cd87238de2cccdaf4e845be5b0c< 6d4a7c0b296162354b6fc759a1475b9d57ddfaa6affected
… +12 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-38680の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen > 2), buf the function accesses buffer[3], requiring at least 4 bytes. This can lead to an out-of-bounds read if the buffer has exactly 3 bytes. Fix it by checking that the buffer has at least 4 bytes in uvc_parse_format().
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于边界检查不足,可能导致1字节越界读取。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux c0efd232929c2cd87238de2cccdaf4e845be5b0c ~ 9ad554217c9b945031c73df4e8176a475e2dea57 -
LinuxLinux 2.6.26 -

II. CVE-2025-38680の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-38680のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-09-04 · 52 CVEs total

CVE-2025-387089.8 CRITICALdrbd: add missing kref_get in handle_write_conflicts
CVE-2025-387249.8 CRITICALnfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
CVE-2025-387289.1 CRITICALsmb3: fix for slab out of bounds on mount to ksmbd
CVE-2025-386888.8 HIGHiommufd: Prevent ALIGN() overflow
CVE-2025-386977.8 HIGHjfs: upper bound check of tree index in dbAllocAG
CVE-2025-387227.8 HIGHhabanalabs: fix UAF in export_dmabuf()
CVE-2025-386857.8 HIGHfbdev: Fix vmalloc out-of-bounds write in fast_imageblit
CVE-2025-387187.8 HIGHsctp: linearize cloned gso packets in sctp_rcv
CVE-2025-387177.8 HIGHnet: kcm: Fix race condition in kcm_unattach()
CVE-2025-387157.8 HIGHhfs: fix slab-out-of-bounds in hfs_bnode_read()
CVE-2025-387107.8 HIGHgfs2: Validate i_depth for exhash directories
CVE-2025-387307.8 HIGHio_uring/net: commit partial buffers on retry
CVE-2025-387037.8 HIGHdrm/xe: Make dma-fences compliant with the safe access rules
CVE-2025-387147.8 HIGHhfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
CVE-2025-386797.3 HIGHmedia: venus: Fix OOB read due to missing payload bound check
CVE-2025-386877.3 HIGHcomedi: fix race between polling and detaching
CVE-2025-387137.1 HIGHhfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
CVE-2025-387077.1 HIGHfs/ntfs3: Add sanity check for file name
CVE-2025-38682i2c: core: Fix double-free of fwnode in i2c_unregister_device()
CVE-2025-38694media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb()

Showing 20 of 52 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-38680へのコメント

まだコメントはありません


コメントを残す