目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-38253— Linux kernel 安全漏洞

CVSS 8.8 · High EPSS 0.20% · P10

Possible ATT&CK Techniques 1AI

T1001 · Data Obfuscation

Affected Version Matrix 8

ベンダープロダクトVersion Rangeステータス
LinuxLinuxfd2a9b29dc9c4c35def91d5d1c5b470843539de6< a4f182ffa30c52ad1c8e12edfb8049ee748c0f1baffected
fd2a9b29dc9c4c35def91d5d1c5b470843539de6< 57a3d82200dbeccd002244b96acad570eeeb731faffected
fd2a9b29dc9c4c35def91d5d1c5b470843539de6< f3054152c12e2eed1e72704aff47b0ea58229584affected
6.8affected
< 6.8unaffected
6.12.36≤ 6.12.*unaffected
6.15.5≤ 6.15.*unaffected
6.16≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-38253の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
HID: wacom: fix crash in wacom_aes_battery_handler()
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix crash in wacom_aes_battery_handler() Commit fd2a9b29dc9c ("HID: wacom: Remove AES power_supply after extended inactivity") introduced wacom_aes_battery_handler() which is scheduled as a delayed work (aes_battery_work). In wacom_remove(), aes_battery_work is not canceled. Consequently, if the device is removed while aes_battery_work is still pending, then hard crashes or "Oops: general protection fault..." are experienced when wacom_aes_battery_handler() is finally called. E.g., this happens with built-in USB devices after resume from hibernate when aes_battery_work was still pending at the time of hibernation. So, take care to cancel aes_battery_work in wacom_remove().
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于wacom_aes_battery_handler中崩溃。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux fd2a9b29dc9c4c35def91d5d1c5b470843539de6 ~ a4f182ffa30c52ad1c8e12edfb8049ee748c0f1b -
LinuxLinux 6.8 -

II. CVE-2025-38253の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-38253のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-07-09 · 26 CVEs total

CVE-2025-382649.8 CRITICALnvme-tcp: sanitize request list handling
CVE-2025-382469.8 CRITICALbnxt: properly flush XDP redirect lists
CVE-2025-382388.8 HIGHscsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out
CVE-2025-382527.8 HIGHcxl/ras: Fix CPER handler device confusion
CVE-2025-382617.8 HIGHriscv: save the SR_SUM status over switches
CVE-2025-382627.8 HIGHtty: serial: uartlite: register uart driver in init
CVE-2025-382507.8 HIGHBluetooth: hci_core: Fix use-after-free in vhci_flush()
CVE-2025-382487.8 HIGHbridge: mcast: Fix use-after-free during router port configuration
CVE-2025-382427.8 HIGHmm: userfaultfd: fix race of userfaultfd_move and swap cache
CVE-2025-382447.5 HIGHsmb: client: fix potential deadlock when reconnecting channels
CVE-2025-382397.3 HIGHscsi: megaraid_sas: Fix invalid node index
CVE-2025-382577.3 HIGHs390/pkey: Prevent overflow in size calculation for memdup_user()
CVE-2025-38256io_uring/rsrc: fix folio unpinning
CVE-2025-38263bcache: fix NULL pointer in cache_set_flush()
CVE-2025-38241mm/shmem, swap: fix softlockup with mTHP swapin
CVE-2025-38260btrfs: handle csum tree error with rescue=ibadroots correctly
CVE-2025-38259ASoC: codecs: wcd9335: Fix missing free of regulator supplies
CVE-2025-38258mm/damon/sysfs-schemes: free old damon_sysfs_scheme_filter->memcg_path on write
CVE-2025-38255lib/group_cpus: fix NULL pointer dereference from group_cpus_evenly()
CVE-2025-38254drm/amd/display: Add sanity checks for drm_edid_raw()

Showing 20 of 26 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-38253へのコメント

まだコメントはありません


コメントを残す