SB2025071175 - Buffer overflow in Linux kernel scsi lpfc driver
Published: July 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2025-38332)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the lpfc_sli4_get_ctl_attr() function in drivers/scsi/lpfc/lpfc_sli.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/003baa7a1a152576d744bd655820449bbdb0248e
- https://git.kernel.org/stable/c/2f63bf0d2b146956a2f2ff3b25cee71019e64561
- https://git.kernel.org/stable/c/34c0a670556b24d36c9f8934227edb819ca5609e
- https://git.kernel.org/stable/c/75ea8375c5a83f46c47bfb3de6217c7589a8df93
- https://git.kernel.org/stable/c/ac7bfaa099ec3e4d7dfd0ab9726fc3bc7911365d
- https://git.kernel.org/stable/c/ae82eaf4aeea060bb736c3e20c0568b67c701d7d
- https://git.kernel.org/stable/c/b699bda5db818b684ff62d140defd6394f38f3d6
- https://git.kernel.org/stable/c/d34f2384d6df11a6c67039b612c2437f46e587e8