CVE-2025-38502: bpf: Fix oob access in cgroup local storage
Published Aug 16, 2025
·Updated
bpf: Fix oob access in cgroup local storage
Affected Software
13 affected componentsFixes available
Linux Linux kernel=
Microsoft azl3 kernel 6.6.96.2-1
Microsoft azl3 kernel 6.6.96.2-2
Microsoft cbl2 kernel 5.15.186.1-1
Microsoft azl3 kernel 6.6.104.2-4
Linux Linux kernel>=5.9<5.15.192
Linux Linux kernel>=5.16<6.1.151
Linux Linux kernel>=6.2<6.6.105
Linux Linux kernel>=6.7<6.12.46
Linux Linux kernel>=6.13<6.16.1
Debian Debian Linux=11.0
All of the following
Siemens Simatic Cn 4100 Firmware<5.0
Siemens SIMATIC CN 4100
Event History
Aug 16, 2025
CVE Published
via MITRE·09:34 AM
Data Sourced
via MITRE·09:34 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·12:58 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·12:58 AM
SeverityAffected Software
Updated
via Microsoft·07:58 AM
DescriptionSeverity
Updated
via Microsoft·07:58 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-38502?
CVE-2025-38502 has a medium severity level due to the potential for out-of-bounds access in the Linux kernel.
2
How do I fix CVE-2025-38502?
To fix CVE-2025-38502, update your Linux kernel to the latest stable version provided by your distribution.
3
Who reported CVE-2025-38502?
CVE-2025-38502 was reported by Lonial.
4
What component is affected by CVE-2025-38502?
CVE-2025-38502 affects the BPF component within the Linux kernel's cgroup local storage.
5
Can CVE-2025-38502 be exploited remotely?
CVE-2025-38502 does not have a direct indication of remote exploitability, but it can be exploited through crafted tail calls.