AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-38395

HIGH · CVSS 8.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-07-25 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.4. It affects Linux.

CVE
CVE-2025-38395
Severity
HIGH
CVSS
8.4
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods drvdata::gpiods is supposed to hold an array of 'gpio_desc' pointers. But the memory is allocated for only one pointer. This will lead to out-of-bounds access later in the code if 'config::ngpios' is > 1. So fix the code to allocate enough memory to hold 'config::ngpios' of GPIO descriptors. While at it, also move the check for memory allocation failure to be below the allocation to make it more readable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)