Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-38332— scsi: lpfc: Use memcpy() for BIOS version

EPSS 0.17% · P7

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinuxb3b4f3e1d575fe142fd437158425c2359b695ff1< ac7bfaa099ec3e4d7dfd0ab9726fc3bc7911365daffected
b3b4f3e1d575fe142fd437158425c2359b695ff1< b699bda5db818b684ff62d140defd6394f38f3d6affected
b3b4f3e1d575fe142fd437158425c2359b695ff1< d34f2384d6df11a6c67039b612c2437f46e587e8affected
b3b4f3e1d575fe142fd437158425c2359b695ff1< 75ea8375c5a83f46c47bfb3de6217c7589a8df93affected
b3b4f3e1d575fe142fd437158425c2359b695ff1< 34c0a670556b24d36c9f8934227edb819ca5609eaffected
b3b4f3e1d575fe142fd437158425c2359b695ff1< 2f63bf0d2b146956a2f2ff3b25cee71019e64561affected
b3b4f3e1d575fe142fd437158425c2359b695ff1< 003baa7a1a152576d744bd655820449bbdb0248eaffected
b3b4f3e1d575fe142fd437158425c2359b695ff1< ae82eaf4aeea060bb736c3e20c0568b67c701d7daffected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-38332

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
scsi: lpfc: Use memcpy() for BIOS version
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Use memcpy() for BIOS version The strlcat() with FORTIFY support is triggering a panic because it thinks the target buffer will overflow although the correct target buffer size is passed in. Anyway, instead of memset() with 0 followed by a strlcat(), just use memcpy() and ensure that the resulting buffer is NULL terminated. BIOSVersion is only used for the lpfc_printf_log() which expects a properly terminated string.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于lpfc驱动中BIOS版本处理不当,可能导致缓冲区溢出。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux b3b4f3e1d575fe142fd437158425c2359b695ff1 ~ ac7bfaa099ec3e4d7dfd0ab9726fc3bc7911365d -
LinuxLinux 5.2 -

II. Public POCs for CVE-2025-38332

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38332

登录查看更多情报信息。

Patches & Fixes for CVE-2025-38332 (1)

Same Patch Batch · Linux · 2025-07-10 · 84 CVEs total

CVE-2025-383259.8 CRITICALksmbd: add free_transport ops in ksmbd connection
CVE-2025-382838.8 HIGHhisi_acc_vfio_pci: bugfix live migration function without VF device driver
CVE-2025-382908.8 HIGHwifi: ath12k: fix node corruption in ar->arvifs list
CVE-2025-382918.8 HIGHwifi: ath12k: Prevent sending WMI commands to firmware during firmware crash
CVE-2025-382938.8 HIGHwifi: ath11k: fix node corruption in ar->arvifs list
CVE-2025-382928.8 HIGHwifi: ath12k: fix invalid access to memory
CVE-2025-383438.3 HIGHwifi: mt76: mt7996: drop fragments with multicast or broadcast RA
CVE-2025-383217.8 HIGHsmb: Log an error when close_all_cached_dirs fails
CVE-2025-383037.8 HIGHBluetooth: eir: Fix possible crashes on eir_create_adv_data
CVE-2025-383337.8 HIGHf2fs: fix to bail out in get_new_segment()
CVE-2025-383177.8 HIGHwifi: ath12k: Fix buffer overflow in debugfs
CVE-2025-383067.8 HIGHfs/fhandle.c: fix a race in call of has_locked_children()
CVE-2025-382787.8 HIGHocteontx2-pf: QOS: Refactor TC_HTB_LEAF_DEL_LAST callback
CVE-2025-383397.8 HIGHpowerpc/bpf: fix JIT code size calculation of bpf trampoline
CVE-2025-382707.8 HIGHnet: drv: netdevsim: don't napi_complete() from netpoll
CVE-2025-383467.8 HIGHftrace: Fix UAF when lookup kallsym after ftrace disabled
CVE-2025-382737.8 HIGHnet: tipc: fix refcount warning in tipc_aead_encrypt
CVE-2025-383417.8 HIGHeth: fbnic: avoid double free when failing to DMA-map FW msg
CVE-2025-382767.8 HIGHfs/dax: Fix "don't skip locked entries when scanning entries"
CVE-2025-382877.5 HIGHIB/cm: Drop lockdep assert and WARN when freeing old msg

Showing top 20 of 84 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38332

No comments yet


Leave a comment