PT-2025-33811 · Linux+1 · Linux Kernel+1

Published

2025-06-23

·

Updated

2025-11-26

·

CVE-2025-38613

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains an issue in the staging/gpib subsystem where an uninitialized padding field within the gpib board info ioctl structure is copied back to userspace via the board info ioctl function. This occurs due to the introduction of a padding field, resulting in unassigned padding fields being present on the stack frame.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Improper Initialization

Weakness Enumeration

Related Identifiers

BDU:2026-02823
CVE-2025-38613

Affected Products

Astra Linux
Linux Kernel