PT-2025-33544 · Linux+4 · Linux Kernel+4

Lonial

·

Published

2025-07-31

·

Updated

2026-05-07

·

CVE-2025-38502

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: An out-of-bounds access issue exists in cgroup local storage within the Linux kernel. This can be triggered via tail calls between two BPF programs utilizing cgroup local storage with differing value sizes. The verifier may not detect the issue during program validation, but a runtime context error can occur where bpf get local storage() retrieves the incorrect map, leading to unintended memory access.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

AZL-66359
AZL-73473
BDU:2025-10441
CVE-2025-38502
DLA-4328-1
DSA-6008-1
DSA-6009-1
ECHO-97CE-48FD-51A9
INFESA-2025_0006
OESA-2025-2268
OESA-2025-2269
OESA-2025-2270
OESA-2025-2272
OESA-2025-2273
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu