PT-2025-37218 · Linux+6 · Linux Kernel+6

Published

2025-06-30

·

Updated

2026-05-26

·

CVE-2025-39760

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains a flaw within the USB core configuration parsing process. Specifically, the usb parse ss endpoint companion() function did not properly validate the size of the descriptor before accessing its fields, potentially leading to an out-of-bounds read. The fix involves checking the descriptor size before accessing any of its fields.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:1661
ALSA-2026:1662
ALSA-2026:2212
ALSA-2026:4012
AZL-67154
AZL-75110
BDU:2025-15213
CVE-2025-39760
DLA-4327-1
DLA-4328-1
DSA-6009-1
ECHO-C95B-2E06-C378
OESA-2025-2465
OESA-2025-2466
OESA-2025-2467
OPENSUSE-SU-2025:20081-1
RHSA-2026:1661
RHSA-2026:1662
RHSA-2026:2212
RHSA-2026:2759
RHSA-2026:2766
RHSA-2026:3124
RHSA-2026:3267
RHSA-2026:3268
RHSA-2026:3277
RHSA-2026:3293
RHSA-2026:3358
RHSA-2026:3360
RHSA-2026:3375
RHSA-2026:3388
RHSA-2026:3634
RHSA-2026:3685
RHSA-2026:4012
SUSE-SU-2025:03600-1
SUSE-SU-2025:03614-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Rocky Linux
Suse
Ubuntu