Wind River Support Network

HomeDefectsLIN1024-10954
Acknowledged

LIN1024-10954 : Security Advisory - linux - CVE-2025-38639

Created: Aug 24, 2025    Updated: Aug 26, 2025
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:EOL][EOL]netfilter: xt_nfacct: don't assume acct name is null-terminated[EOL][EOL]BUG: KASAN: slab-out-of-bounds in .. lib/vsprintf.c:721[EOL]Read of size 1 at addr ffff88801eac95c8 by task syz-executor183/5851[EOL][..][EOL] string+0x231/0x2b0 lib/vsprintf.c:721[EOL] vsnprintf+0x739/0xf00 lib/vsprintf.c:2874[EOL] [..][EOL] nfacct_mt_checkentry+0xd2/0xe0 net/netfilter/xt_nfacct.c:41[EOL] xt_check_match+0x3d1/0xab0 net/netfilter/x_tables.c:523[EOL][EOL]nfnl_acct_find_get() handles non-null input, but the error[EOL]printk relied on its presence.

CREATE(Triage):(User=pbi-cn) [CVE-2025-38639 (https://nvd.nist.gov/vuln/detail/CVE-2025-38639)
Live chat
Online