CVE-2025-38078
MEDIUM EPSS 2.0%
Published Jun 18, 20251y ago · Modified Jun 17, 20261w ago
4.7 CVSS 3.1
Published Jun 18, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix race of buffer access at PCM OSS layer The PCM OSS layer tries to clear the buffer with the silence data at initialization (or reconfiguration) of a stream with the explicit call of snd_pcm_format_set_silence() with runtime->dma_area. But this may lead to a UAF because the accessed runtime->dma_area might be freed concurrently, as it's performed outside the PCM ops. For avoiding it, move the code into the PCM core and perform it inside the buffer access lock, so that it won't be changed during the operation.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
2.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-362
Affected Products 15
| Vendor | Product | Version | Range |
|---|---|---|---|
| linux | linux_kernel | * | <5.4.294 |
| linux | linux_kernel | * | ≥5.5 – <5.10.238 |
| linux | linux_kernel | * | ≥5.11 – <5.15.185 |
| linux | linux_kernel | * | ≥5.16 – <6.1.141 |
| linux | linux_kernel | * | ≥6.2 – <6.6.93 |
| linux | linux_kernel | * | ≥6.7 – <6.12.31 |
| linux | linux_kernel | * | ≥6.13 – <6.14.9 |
| linux | linux_kernel | 6.15 | any |
| linux | linux_kernel | 6.15 | any |
| linux | linux_kernel | 6.15 | any |
| linux | linux_kernel | 6.15 | any |
| linux | linux_kernel | 6.15 | any |
| linux | linux_kernel | 6.15 | any |
| linux | linux_kernel | 6.15 | any |
| debian | debian_linux | 11.0 | any |
References 10
- git.kernel.org https://git.kernel.org/stable/c/10217da9644ae75cea7330f902c35fc5ba78bbbf
- git.kernel.org https://git.kernel.org/stable/c/74d90875f3d43f3eff0e9861c4701418795d3455
- git.kernel.org https://git.kernel.org/stable/c/8170d8ec4efd0be352c14cb61f374e30fb0c2a25
- git.kernel.org https://git.kernel.org/stable/c/93a81ca0657758b607c3f4ba889ae806be9beb73
- git.kernel.org https://git.kernel.org/stable/c/afa56c960fcb4db37f2e3399f28e9402e4e1f470
- git.kernel.org https://git.kernel.org/stable/c/bf85e49aaf3a3c5775ea87369ea5f159c2148db4
- git.kernel.org https://git.kernel.org/stable/c/c0e05a76fc727929524ef24a19c302e6dd40233f
- git.kernel.org https://git.kernel.org/stable/c/f3e14d706ec18faf19f5a6e75060e140fea05d4a
- lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
Remediation
- git.kernel.org https://git.kernel.org/stable/c/10217da9644ae75cea7330f902c35fc5ba78bbbf
- git.kernel.org https://git.kernel.org/stable/c/74d90875f3d43f3eff0e9861c4701418795d3455
- git.kernel.org https://git.kernel.org/stable/c/8170d8ec4efd0be352c14cb61f374e30fb0c2a25
- git.kernel.org https://git.kernel.org/stable/c/93a81ca0657758b607c3f4ba889ae806be9beb73
- git.kernel.org https://git.kernel.org/stable/c/afa56c960fcb4db37f2e3399f28e9402e4e1f470
- git.kernel.org https://git.kernel.org/stable/c/bf85e49aaf3a3c5775ea87369ea5f159c2148db4
- git.kernel.org https://git.kernel.org/stable/c/c0e05a76fc727929524ef24a19c302e6dd40233f
- git.kernel.org https://git.kernel.org/stable/c/f3e14d706ec18faf19f5a6e75060e140fea05d4a