CVE-2025-38484: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: iio: backend: fix out-of-bound write The buffer is set to 80 character. If a caller write more characters, count is truncated to the max available space in "simple_write_to_buffer". But afterwards a string terminator is written to the buffer at offset count without boundary check. The zero termination is written OUT-OF-BOUND. Add a check that the given buffer is smaller then the buffer to prevent.

Affected products

  • Linux Linux Kernel: from 6.12.23, before 6.12.40 (fixed in 6.12.40); from 6.13.11, before 6.14 (fixed in 6.14); from 6.14.2, before 6.15.8 (fixed in 6.15.8); version 6.16 only

Published 2025-07-28. Last modified 2026-07-30.