CVE-2025-38613 – Linux Kernel GPib Buffer Overflow

The following table lists the changes that have been made to the
CVE-2025-38613 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 19, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    staging: gpib: fix unset padding field copy back to userspace

    The introduction of a padding field in the gpib_board_info_ioctl is
    showing up as initialized data on the stack frame being copyied back
    to userspace in function board_info_ioctl. The simplest fix is to
    initialize the entire struct to zero to ensure all unassigned padding
    fields are zero’d before being copied back to userspace.

    Added Reference https://git.kernel.org/stable/c/19dedd4f70f5a6505e7c601ef7dd40542d1d9aa5
    Added Reference https://git.kernel.org/stable/c/a739d3b13bff0dfa1aec679d08c7062131a2a425
Share the Post:

Related Posts