Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-38380

Опубликовано: 25 июл. 2025
Источник: redhat
CVSS3: 7

Описание

No description is available for this CVE.

Отчет

This vulnerability exists in the driver for certain hardware which supports the I2C protocol. This hardware is often used to interface with low-speed peripherals such as human interface devices. By exploiting a flaw in how the hardware handles certain messages, an attacker could craft malicious messages to cause a system crash or to modify or expose sensitive memory locations. This vulnerability has a security impact of Important because of its impact on system Confidentiality, Integrity, and Availability, and the fact that only local privileges are required (PR:L). This vulnerability exists in Red Hat Enterprise Linux 8 and later in the i2c-designware-core module.

Меры по смягчению последствий

To mitigate this issue, prevent the i2c-designware-core module from being loaded. Please see https://access.redhat.com/solutions/41278 for details on how to prevent a kernel module from loading automatically.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernel-rtAffected
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 10kernelFixedRHSA-2025:1400918.08.2025
Red Hat Enterprise Linux 8kernelFixedRHSA-2025:1396018.08.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportkernelFixedRHSA-2025:1377613.08.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicekernelFixedRHSA-2025:1377613.08.2025
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionskernelFixedRHSA-2025:1377613.08.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-908
https://bugzilla.redhat.com/show_bug.cgi?id=2383381kernel: i2c/designware: Fix an initialization issue

7 High

CVSS3

Связанные уязвимости

ubuntu
3 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

nvd
3 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

msrc
2 месяца назад

i2c/designware: Fix an initialization issue

github
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: i2c/designware: Fix an initialization issue The i2c_dw_xfer_init() function requires msgs and msg_write_idx from the dev context to be initialized. amd_i2c_dw_xfer_quirk() inits msgs and msgs_num, but not msg_write_idx. This could allow an out of bounds access (of msgs). Initialize msg_write_idx before calling i2c_dw_xfer_init().

CVSS3: 7
fstec
4 месяца назад

Уязвимость функции i2c_dw_xfer_init() модуля drivers/i2c/busses/i2c-designware-master.c ядра операционных систем Linux, позволяющая нарушителю вызвать отказ в обслуживании

7 High

CVSS3