SB2025072779 - Buffer overflow in Linux kernel char ipmi driver
Published: July 27, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2025-38456)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the ipmi_create_user() function in drivers/char/ipmi/ipmi_msghandler.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/7c1a6ddb99858e7d68961f74ae27caeeeca67b6a
- https://git.kernel.org/stable/c/9e0d33e75c1604c3fad5586ad4dfa3b2695a3950
- https://git.kernel.org/stable/c/cbc1670297f675854e982d23c8583900ff0cc67a
- https://git.kernel.org/stable/c/e2d5c005dfc96fe857676d1d8ac46b29275cb89b
- https://git.kernel.org/stable/c/fa332f5dc6fc662ad7d3200048772c96b861cf6b