PT-2025-50713 · Google · Tracepoint Ipc.C

Published

2025-12-11

·

Updated

2026-01-05

·

CVE-2025-36932

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions versions prior to 2025-36932
Description A flaw exists in the tracepoint msg handler function within cpm/google/lib/tracepoint/tracepoint ipc.c. This issue is due to insufficient input validation, potentially leading to a memory overwrite. Successful exploitation of this could allow a local user to gain elevated privileges without requiring additional permissions or user interaction. The vulnerable component is the tracepoint msg handler function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-36932

Affected Products

Tracepoint Ipc.C