PT-2025-39145 · Linux+1 · Linux Kernel+1

Published

2025-08-27

·

Updated

2025-09-24

·

CVE-2025-39888

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw related to fuse. Specifically, a slab-out-of-bounds write condition was identified in the fuse dev do write function. This issue occurs when the number of bytes to be retrieved is truncated and an offset is present, potentially leading to an overrun. A loop termination condition has been added to prevent this.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-13900
CVE-2025-39888

Affected Products

Astra Linux
Linux Kernel