CVE-2025-38667: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: iio: fix potential out-of-bound write The buffer is set to 20 characters. If a caller write more characters, count is truncated to the max available space in "simple_write_to_buffer". To protect from OoB access, check that the input size fit into buffer and add a zero terminator after copy to the end of the copied data.

Affected products

  • Linux Linux Kernel: from 6.15, before 6.15.9 (fixed in 6.15.9); version 6.16 only

Published 2025-08-22. Last modified 2026-07-30.