CVE-2025-38497 Details
Description
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Fix OOB read on empty string write When writing an empty string to either 'qw_sign' or 'landingPage' sysfs attributes, the store functions attempt to access page[l - 1] before validating that the length 'l' is greater than zero. This patch fixes the vulnerability by adding a check at the beginning of os_desc_qw_sign_store() and webusb_landingPage_store() to handle the zero-length input case gracefully by returning immediately.
An out-of-bounds read vulnerability has been identified in the Linux kernel's USB gadget configuration filesystem. This issue arises when an empty string is written to the 'qw_sign' or 'landingPage' sysfs attributes. The store functions attempt to access the last character of the string before confirming that the string length is greater than zero, leading to a potential out-of-bounds read. The vulnerability has been addressed by adding a length check to handle zero-length inputs appropriately, preventing the out-of-bounds access.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/15a87206879951712915c03c8952a73d6a74721e | kernel.org | Patch |
| https://git.kernel.org/stable/c/22b7897c289cc25d99c603f5144096142a30d897 | kernel.org | Patch |
| https://git.kernel.org/stable/c/2798111f8e504ac747cce911226135d50b8de468 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3014168731b7930300aab656085af784edc861f6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/58bdd5160184645771553ea732da5c2887fc9bd1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/783ea37b237a9b524f1e5ca018ea17d772ee0ea0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/78b41148cfea2a3f04d87adf3a71b21735820a37 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d68b7c8fefbaeae8f065b84e40cf64baf4cc0c76 | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html | CVE | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html | CVE | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.16, < 5.4.297 >= 5.5, < 5.10.241 >= 5.11, < 5.15.190 >= 5.16, < 6.1.147 >= 6.2, < 6.6.100 >= 6.7, < 6.12.40 >= 6.13, < 6.15.8 6.16 rc1 6.16 rc2 6.16 rc3 6.16 rc4 6.16 rc5 6.16 rc6 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jan 7, 2026 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 28, 2025 | CVE Modified | kernel.org |
| Jul 28, 2025 | New CVE Received | kernel.org |