Review reviewHigh

CVE-2025-38226

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: media: vivid: Change the siize of the composing syzkaller found a bug: BUG: KASAN: vmalloc-out-of-bounds in tpg_fill_plane_pattern drivers/media/common/v4l2-tpg/v4l2-tpg-core.c:2608 [inline] BUG: KASAN: vmalloc-out-of-bounds in tpg_fill_plane_buffer+0x1a9c/0x5af0 drivers/media/common/v4l2-tpg/v4l2-tpg-core.c:2705 Write of size 1440 at addr ffffc9000d0ffda0 by task vivid-000-vid-c/5304 CPU: 0 UID: 0 PID: 5304 Comm: vivid-000-vid-c Not tainted 6.14.0-rc2-syzkaller-00039-g09fbf3d50205 #0 Hardware name: QEMU Standard PC (Q35 +...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2025.07.04
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: media: vivid: Change the siize of the composing syzkaller found a bug: BUG: KASAN: vmalloc-out-of-bounds in tpg_fill_plane_pattern drivers/media/common/v4l2-tpg/v4l2-tpg-core.c:2608 [inline] BUG: KASAN: vmalloc-out-of-bounds in tpg_fill_plane_buffer+0x1a9c/0x5af0 drivers/media/common/v4l2-tpg/v4l2-tpg-core.c:2705 Write of size 1440 at addr ffffc9000d0ffda0 by task vivid-000-vid-c/5304 CPU: 0 UID: 0 PID: 5304 Comm: vivid-000-vid-c Not tainted 6.14.0-rc2-syzkaller-00039-g09fbf3d50205 #0 Hardware name: QEMU Standard PC (Q35 +...

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 54f259906039dbfe46c550011409fa16f72370f6 < 57597d8db5bbda618ba2145b7e8a7e6f01b6a27e, >= f9d19f3a044ca651b0be52a4bf951ffe74259b9f < 635cea4f44c1ddae208666772c164eab5a6bce39, >= ab54081a2843aefb837812fac5488cc8f1696142 < 89b5ab822bf69867c3951dd0eb34b0314c38966b, >= 2f558c5208b0f70c8140e08ce09fcc84da48e789 < 5d89aa42534723400fefd46e26e053b9c382b4ee, >= 94a7ad9283464b75b12516c5512541d467cefcf8 < f6b1b0f8ba0b61d8b511df5649d57235f230c135, >= 94a7ad9283464b75b12516c5512541d467cefcf8 < 00da1c767a6567e56f23dda586847586868ac064, >= 94a7ad9283464b75b12516c5512541d467cefcf8 < c56398885716d97ee9bcadb2bc9663a8c1757a34, >= 94a7ad9283464b75b12516c5512541d467cefcf8 < f83ac8d30c43fd902af7c84c480f216157b60ef0, >= 8c0ee15d9a102c732d0745566d254040085d5663, >= 5edc3604151919da8da0fb092b71d7dce07d848a, >= 9c7fba9503b826f0c061d136f8f0c9f953ed18b9, >= ccb5392c4fea0e7d9f7ab35567e839d74cb3998b, >= 5.4.229 < 5.4.296, >= 5.10.163 < 5.10.239, >= 5.15.86 < 5.15.186, >= 6.1.2 < 6.1.142, >= 4.9.337 < 4.10, >= 4.14.303 < 4.15, >= 4.19.270 < 4.20, >= 6.0.16 < 6.1
Fixed versions
4.10, 4.15, 4.20, 5.4.296, 5.10.239, 5.15.186, 6.1, 6.1.142, 6.6.95, 6.12.35, 6.15.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-787