SB2025090510 - Buffer overflow in Linux kernel block driver
Published: September 5, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2025-38709)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the loop_set_dio(), loop_set_block_size(), lo_simple_ioctl() and lo_ioctl() functions in drivers/block/loop.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/139a000d20f2f38ce34296feddd641d730fe1c08
- https://git.kernel.org/stable/c/5d67b30aefeb7a949040bbb1b4e3b84c5d29a624
- https://git.kernel.org/stable/c/7e49538288e523427beedd26993d446afef1a6fb
- https://git.kernel.org/stable/c/b928438cc87c0bf7ae078e4b7b6e14261e84c5c5
- https://git.kernel.org/stable/c/ce8da5d13d8c2a7b30b2fb376a22e8eb1a70b8bb