CVE-2025-38003: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is generated for a bcm_op which is in the process to be removed the procfs output might show unreliable data (UAF). As the removal of bcm_op's is already implemented with rcu handling this patch adds the missing rcu_read_lock() and makes sure the list entries are properly removed under rcu protection.
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: from 4.19.252, before 4.20 (fixed in 4.20); from 5.4.205, before 5.4.294 (fixed in 5.4.294); from 5.10.130, before 5.10.238 (fixed in 5.10.238); from 5.15.54, before 5.15.185 (fixed in 5.15.185); from 5.18.11, before 5.19 (fixed in 5.19); from 5.19.1, before 6.1.141 (fixed in 6.1.141); …
Published 2025-06-08. Last modified 2026-07-30.