Executive Summary

Informations
Name CVE-2025-38257 First vendor Publication 2025-07-09
Vendor Cve Last vendor Modification 2025-07-10

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

s390/pkey: Prevent overflow in size calculation for memdup_user()

Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow.

In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later.

Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations.

Found by Linux Verification Center (linuxtesting.org).

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-38257

Sources (Detail)

https://git.kernel.org/stable/c/73483ca7e07a5e39bdf612eec9d3d293e8bef649
https://git.kernel.org/stable/c/7360ee47599af91a1d5f4e74d635d9408a54e489
https://git.kernel.org/stable/c/88f3869649edbc4a13f6c2877091f81cd5a50f05
https://git.kernel.org/stable/c/ad1bdd24a02d5a8d119af8e4cd50933780a6d29f
https://git.kernel.org/stable/c/f855b119e62b004a5044ed565f2a2b368c4d3f16
https://git.kernel.org/stable/c/faa1ab4a23c42e34dc000ef4977b751d94d5148c
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2025-07-10 21:20:34
  • Multiple Updates
2025-07-09 17:20:33
  • First insertion