目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-38559— Linux kernel 安全漏洞

AI Predicted 3.3 Difficulty: Easy EPSS 0.15% · P5

Affected Version Matrix 10

ベンダープロダクトVersion Rangeステータス
LinuxLinux045a513040cc0242d364c05c3791594e2294f32d< 860d93bd6a21f08883711196344c353bc3936a2baffected
045a513040cc0242d364c05c3791594e2294f32d< 18d53b543b5447478e259c96ca4688393f327c98affected
045a513040cc0242d364c05c3791594e2294f32d< 089d05266b2caf020ac2ae2cd2be78f580268f5daffected
045a513040cc0242d364c05c3791594e2294f32d< 54d5cd4719c5e87f33d271c9ac2e393147d934f8affected
6.12affected
< 6.12unaffected
6.12.42≤ 6.12.*unaffected
6.15.10≤ 6.15.*unaffected
… +2 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-38559の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
platform/x86/intel/pmt: fix a crashlog NULL pointer access
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmt: fix a crashlog NULL pointer access Usage of the intel_pmt_read() for binary sysfs, requires a pcidev. The current use of the endpoint value is only valid for telemetry endpoint usage. Without the ep, the crashlog usage causes the following NULL pointer exception: BUG: kernel NULL pointer dereference, address: 0000000000000000 Oops: Oops: 0000 [#1] SMP NOPTI RIP: 0010:intel_pmt_read+0x3b/0x70 [pmt_class] Code: Call Trace: <TASK> ? sysfs_kf_bin_read+0xc0/0xe0 kernfs_fop_read_iter+0xac/0x1a0 vfs_read+0x26d/0x350 ksys_read+0x6b/0xe0 __x64_sys_read+0x1d/0x30 x64_sys_call+0x1bc8/0x1d70 do_syscall_64+0x6d/0x110 Augment struct intel_pmt_entry with a pointer to the pcidev to avoid the NULL pointer exception.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未正确设置pcidev指针,可能导致空指针取消引用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 045a513040cc0242d364c05c3791594e2294f32d ~ 860d93bd6a21f08883711196344c353bc3936a2b -
LinuxLinux 6.12 -

II. CVE-2025-38559の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-38559のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-08-19 · 59 CVEs total

CVE-2025-385619.8 CRITICALksmbd: fix Preauh_HashValue race condition
CVE-2025-385669.8 CRITICALsunrpc: fix handling of server side tls alerts
CVE-2025-385609.3 CRITICALx86/sev: Evict cache lines during SNP memory validation
CVE-2025-386018.8 HIGHwifi: ath11k: clear initialized flag for deinit-ed srng lists
CVE-2025-386008.8 HIGHwifi: mt76: mt7925: fix off by one in mt7925_mcu_hw_scan()
CVE-2025-385998.8 HIGHwifi: mt76: mt7996: Fix possible OOB access in mt7996_tx()
CVE-2025-385928.8 HIGHBluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv
CVE-2025-386088.6 HIGHbpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
CVE-2025-385748.6 HIGHpptp: ensure minimal skb length in pptp_xmit()
CVE-2025-385718.2 HIGHsunrpc: fix client side handling of tls alerts
CVE-2025-385957.8 HIGHxen: fix UAF in dmabuf_exp_from_pages()
CVE-2025-385807.8 HIGHext4: fix inode use after free in ext4_end_io_rsv_work()
CVE-2025-386077.8 HIGHbpf: handle jset (if a & b ...) as a jump in CFG computation
CVE-2025-386147.8 HIGHeventpoll: Fix semi-unbounded recursion
CVE-2025-386157.8 HIGHfs/ntfs3: cancle set bad inode after removing name fails
CVE-2025-386047.8 HIGHwifi: rtl818x: Kill URBs before clearing tx status queue
CVE-2025-385937.8 HIGHBluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()'
CVE-2025-385867.8 HIGHbpf, arm64: Fix fp initialization for exception boundary
CVE-2025-385827.8 HIGHRDMA/hns: Fix double destruction of rsv_qp
CVE-2025-385557.8 HIGHusb: gadget : fix use-after-free in composite_dev_cleanup()

Showing 20 of 59 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-38559へのコメント

まだコメントはありません


コメントを残す