目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-39786— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.13% · P3

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 6

ベンダープロダクトVersion Rangeステータス
LinuxLinux031bdc8aee01b7b298159eee541844d8bff4467d< 2def1a8691eb43654da0ae0d2fdb3722e20262a5affected
031bdc8aee01b7b298159eee541844d8bff4467d< 0eb8d7b25397330beab8ee62c681975b79f37223affected
6.14affected
< 6.14unaffected
6.16.4≤ 6.16.*unaffected
6.17≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-39786の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
iio: adc: ad7173: fix channels index for syscalib_mode
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7173: fix channels index for syscalib_mode Fix the index used to look up the channel when accessing the syscalib_mode attribute. The address field is a 0-based index (same as scan_index) that it used to access the channel in the ad7173_channels array throughout the driver. The channels field, on the other hand, may not match the address field depending on the channel configuration specified in the device tree and could result in an out-of-bounds access.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于使用错误的索引访问syscalib_mode属性,可能导致越界访问。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 031bdc8aee01b7b298159eee541844d8bff4467d ~ 2def1a8691eb43654da0ae0d2fdb3722e20262a5 -
LinuxLinux 6.14 -

II. CVE-2025-39786の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-39786のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-09-11 · 54 CVEs total

CVE-2025-397589.8 CRITICALRDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages
CVE-2025-397618.8 HIGHwifi: ath12k: Decrement TID on RX peer frag setup error handling
CVE-2025-397508.8 HIGHwifi: ath12k: Correct tid cleanup when tid setup fails
CVE-2025-397908.4 HIGHbus: mhi: host: Detect events pointing to unexpected TREs
CVE-2025-397917.8 HIGHdm: dm-crypt: Do not partially accept write BIOs with zoned targets
CVE-2025-397797.8 HIGHbtrfs: subpage: keep TOWRITE tag until folio is cleaned
CVE-2025-397877.8 HIGHsoc: qcom: mdt_loader: Ensure we don't read past the ELF header
CVE-2025-397407.8 HIGHdrm/xe/migrate: prevent potential UAF
CVE-2025-397857.8 HIGHdrm/hisilicon/hibmc: fix irq_request()'s irq name variable is local
CVE-2025-397807.8 HIGHsched/ext: Fix invalid task state transitions on class switch
CVE-2025-397707.5 HIGHnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
CVE-2025-397387.3 HIGHbtrfs: do not allow relocation of partially dropped subvolumes
CVE-2025-397897.3 HIGHcrypto: x86/aegis - Add missing error checks
CVE-2025-397767.0 HIGHmm/debug_vm_pgtable: clear page table entries at destroy_args()
CVE-2025-39768net/mlx5: HWS, fix complex rules rehash error flow
CVE-2025-39773net: bridge: fix soft lockup in br_multicast_query_expired()
CVE-2025-39772drm/hisilicon/hibmc: fix the hibmc loaded failed bug
CVE-2025-39766net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit
CVE-2025-39769bnxt_en: Fix lockdep warning during rmmod
CVE-2025-39771regulator: pca9450: Use devm_register_sys_off_handler

Showing 20 of 54 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-39786へのコメント

まだコメントはありません


コメントを残す