Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix access outside of user given buffer in pktgen_thread_write() Honour the user given buffer size for the strn_len() calls (otherwise strn_len() will access memory outside of the user given buffer).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.4.294 |
| Debian | Debian Linux | 11.0 |
References
- https://git.kernel.org/stable/c/128cdb617a87767c29be43e4431129942fce41dfPatch
- https://git.kernel.org/stable/c/425e64440ad0a2f03bdaf04be0ae53dededbaa77Patch
- https://git.kernel.org/stable/c/5bfa81539e22af4c40ae5d43d7212253462383a6Patch
- https://git.kernel.org/stable/c/6b1d3e9db82d01a88de1795b879df67c2116b4f4Patch
- https://git.kernel.org/stable/c/8fef258b555c75a467a6b4b7e3a3cbc46d5f4102Patch
- https://git.kernel.org/stable/c/a3d89f1cfe1e6d4bb164db2595511fd33db21900Patch
- https://git.kernel.org/stable/c/c81c2ee1c3b050ed5c4e92876590cc7a259183f6Patch
- https://git.kernel.org/stable/c/ef1158a6a650ecee72ab40851b1d52e04d3f9cb5Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlThird Party Advisory
FAQ
What is CVE-2025-38061?
CVE-2025-38061 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix access outside of user given buffer in pktgen_thread_write() Honour the user given buffer size for the strn_len()...
How severe is CVE-2025-38061?
CVE-2025-38061 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-38061?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.