Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args() software_node_get_reference_args() wants to get @index-th element, so the property value requires at least '(index + 1) * sizeof(*ref)' bytes but that can not be guaranteed by current OOB check, and may cause OOB for malformed property. Fix by using as OOB check '((index + 1) * sizeof(*ref) > prop->length)'.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.0, < 5.10.239 |
| Debian | Debian Linux | 11.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/142acd739eb6f08c148a96ae8309256f1422ff4bPatch
- https://git.kernel.org/stable/c/31e4e12e0e9609850cefd4b2e1adf782f56337d6Patch
- https://git.kernel.org/stable/c/4b3383110b6df48e0ba5936af2cb68d5eb6bd43bPatch
- https://git.kernel.org/stable/c/56ce76e8d406cc72b89aee7931df5cf3f18db49dPatch
- https://git.kernel.org/stable/c/7af18e42bdefe1dba5bcb32555a4d524fd504939Patch
- https://git.kernel.org/stable/c/9324127b07dde8529222dc19233aa57ec810856cPatch
- https://git.kernel.org/stable/c/f9397cf7bfb680799fb8c7f717c8f756384c3280Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
FAQ
What is CVE-2025-38342?
CVE-2025-38342 is a vulnerability with a CVSS score of 7.1 (HIGH). In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args() software_node_get_reference_args() wants to get @index-th...
How severe is CVE-2025-38342?
CVE-2025-38342 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-38342?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.