VDB

CISA-2025-39815

CISA-2025-39815 PUBLISHED CVSS 5.5 MEDIUM

Reported by Linux · Published September 16, 2025

In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb The userspace load can put up to 2048 bits into an xlen bit stack buffer. We want only xlen bits, so check the size beforehand.

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
LinuxLinux2fa290372dfe7dd248b1c16f943f273a3e674f22, 2fa290372dfe7dd248b1c16f943f273a3e674f22, 2fa290372dfe7dd248b1c16f943f273a3e674f22
LinuxLinux6.8, 0, 6.12.45
linuxlinux_kernel6.8, 6.8, 6.8
LinuxLinux2fa290372dfe7dd248b1c16f943f273a3e674f22, 6.8, 0

Timeline

  • Sep 16, 2025 CVE Published
  • Jan 14, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›