目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-38480— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 中等 EPSS 0.16% · P5

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinuxed9eccbe8970f6eedc1b978c157caf1251a896d4< 4c2981bf30401adfcdbfece4ab6f411f7c5875a1affected
ed9eccbe8970f6eedc1b978c157caf1251a896d4< 16256d7efcf7acc9f39abe21522c4c6b77f67c00affected
ed9eccbe8970f6eedc1b978c157caf1251a896d4< c53570e62b5b28bdb56bb563190227f8307817a5affected
ed9eccbe8970f6eedc1b978c157caf1251a896d4< 3050d197d6bc9ef128944a70210f42d2430b3000affected
ed9eccbe8970f6eedc1b978c157caf1251a896d4< 10f9024a8c824a41827fff1fefefb314c98e2c88affected
ed9eccbe8970f6eedc1b978c157caf1251a896d4< 2af1e7d389c2619219171d23f5b96dbcbb7f9656affected
ed9eccbe8970f6eedc1b978c157caf1251a896d4< 3ab55ffaaf75d0c7b68e332c1cdcc1b0e0044870affected
ed9eccbe8970f6eedc1b978c157caf1251a896d4< e9cb26291d009243a4478a7ffb37b3a9175bfce9affected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-38480 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
comedi: Fix use of uninitialized data in insn_rw_emulate_bits()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: comedi: Fix use of uninitialized data in insn_rw_emulate_bits() For Comedi `INSN_READ` and `INSN_WRITE` instructions on "digital" subdevices (subdevice types `COMEDI_SUBD_DI`, `COMEDI_SUBD_DO`, and `COMEDI_SUBD_DIO`), it is common for the subdevice driver not to have `insn_read` and `insn_write` handler functions, but to have an `insn_bits` handler function for handling Comedi `INSN_BITS` instructions. In that case, the subdevice's `insn_read` and/or `insn_write` function handler pointers are set to point to the `insn_rw_emulate_bits()` function by `__comedi_device_postconfig()`. For `INSN_WRITE`, `insn_rw_emulate_bits()` currently assumes that the supplied `data[0]` value is a valid copy from user memory. It will at least exist because `do_insnlist_ioctl()` and `do_insn_ioctl()` in "comedi_fops.c" ensure at lease `MIN_SAMPLES` (16) elements are allocated. However, if `insn->n` is 0 (which is allowable for `INSN_READ` and `INSN_WRITE` instructions, then `data[0]` may contain uninitialized data, and certainly contains invalid data, possibly from a different instruction in the array of instructions handled by `do_insnlist_ioctl()`. This will result in an incorrect value being written to the digital output channel (or to the digital input/output channel if configured as an output), and may be reflected in the internal saved state of the channel. Fix it by returning 0 early if `insn->n` is 0, before reaching the code that accesses `data[0]`. Previously, the function always returned 1 on success, but it is supposed to be the number of data samples actually read or written up to `insn->n`, which is 0 in this case.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于insn_rw_emulate_bits函数中使用未初始化数据。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux ed9eccbe8970f6eedc1b978c157caf1251a896d4 ~ 4c2981bf30401adfcdbfece4ab6f411f7c5875a1 -
LinuxLinux 2.6.29 -

二、漏洞 CVE-2025-38480 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-38480 的情报信息

登录查看更多情报信息。

同批安全公告 · Linux · 2025-07-28 · 共 29 条

CVE-2025-384909.8 CRITICALLinux kernel 安全漏洞
CVE-2025-384889.8 CRITICALLinux kernel 安全漏洞
CVE-2025-384719.8 CRITICALLinux kernel 安全漏洞
CVE-2025-384729.8 CRITICALLinux kernel 安全漏洞
CVE-2025-384769.8 CRITICALLinux kernel 安全漏洞
CVE-2025-384958.8 HIGHLinux kernel 安全漏洞
CVE-2025-384918.2 HIGHLinux kernel 安全漏洞
CVE-2025-384787.8 HIGHLinux kernel 安全漏洞
CVE-2025-384857.8 HIGHLinux kernel 安全漏洞
CVE-2025-384867.8 HIGHLinux kernel 安全漏洞
CVE-2025-384847.8 HIGHLinux kernel 安全漏洞
CVE-2025-384947.8 HIGHLinux kernel 安全漏洞
CVE-2025-384777.8 HIGHLinux kernel 安全漏洞
CVE-2025-384757.8 HIGHLinux kernel 安全漏洞
CVE-2025-384707.8 HIGHLinux kernel 安全漏洞
CVE-2025-38493Linux kernel 安全漏洞
CVE-2025-38492Linux kernel 安全漏洞
CVE-2025-38497Linux kernel 安全漏洞
CVE-2025-38496Linux kernel 多款产品安全漏洞
CVE-2025-38468Linux kernel 安全漏洞

显示前 20 条,共 29 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38480

暂无评论


发表评论