CVE-2025-38286

HIGH EPSS 7.1%
Published Jul 10, 202511mo ago · Modified Jun 17, 20262w ago
7.1 CVSS 3.1
High
Find Similar
Published Jul 10, 2025 11mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91: Fix possible out-of-boundary access at91_gpio_probe() doesn't check that given OF alias is not available or something went wrong when trying to get it. This might have consequences when accessing gpio_chips array with that value as an index. Note, that BUG() can be compiled out and hence won't actually perform the required checks.

CVSS Details

Base Score
7.1
Exploitability
1.8
Impact
5.2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
7.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-125 Out-of-bounds Read Memory Safety

Affected Products 8

VendorProductVersionRange
linuxlinux_kernel*≥3.8  –  <5.4.295
linuxlinux_kernel*≥5.5  –  <5.10.239
linuxlinux_kernel*≥5.11  –  <5.15.186
linuxlinux_kernel*≥5.16  –  <6.1.142
linuxlinux_kernel*≥6.2  –  <6.6.94
linuxlinux_kernel*≥6.7  –  <6.12.34
linuxlinux_kernel*≥6.13  –  <6.15.3
debiandebian_linux11.0any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/264a5cf0c422e65c94447a1ebebfac7c92690670
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/288c39286f759314ee8fb3a80a858179b4f306da
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2ecafe59668d2506a68459a9d169ebe41a147a41
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/762ef7d1e6eefad9896560bfcb9bcf7f1b6df9c1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/db5665cbfd766db7d8cd0e5fd6e3c0b412916774
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e02e12d6a7ab76c83849a4122785650dc7edef65
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/eb435bc4c74acbb286cec773deac13d117d3ef39
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f1c1fdc41fbf7e308ced9c86f3f66345a3f6f478
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
    Mailing ListThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/264a5cf0c422e65c94447a1ebebfac7c92690670
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/288c39286f759314ee8fb3a80a858179b4f306da
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2ecafe59668d2506a68459a9d169ebe41a147a41
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/762ef7d1e6eefad9896560bfcb9bcf7f1b6df9c1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/db5665cbfd766db7d8cd0e5fd6e3c0b412916774
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e02e12d6a7ab76c83849a4122785650dc7edef65
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/eb435bc4c74acbb286cec773deac13d117d3ef39
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f1c1fdc41fbf7e308ced9c86f3f66345a3f6f478
    Patch