In the Linux kernel, the following vulnerability has been resolved:
iommu: Fix two issues in iommu_copy_struct_from_user()
In the review for iommu_copy_struct_to_user() helper, Matt pointed out that
a NULL pointer should be rejected prior to dereferencing it:
https://lore.kernel.org/all/[email protected]
And Alok pointed out a typo at the same time:
https://lore.kernel.org/all/[email protected]
Since both issues were copied from iommu_copy_struct_from_user(), fix them
first in the current header.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.15:rc4:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 21 May 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 20 May 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Linux kernel, the following vulnerability has been resolved: iommu: Fix two issues in iommu_copy_struct_from_user() In the review for iommu_copy_struct_to_user() helper, Matt pointed out that a NULL pointer should be rejected prior to dereferencing it: https://lore.kernel.org/all/[email protected] And Alok pointed out a typo at the same time: https://lore.kernel.org/all/[email protected] Since both issues were copied from iommu_copy_struct_from_user(), fix them first in the current header. | |
| Title | iommu: Fix two issues in iommu_copy_struct_from_user() | |
| References |
|
Status: PUBLISHED
Assigner: Linux
Published: 2025-05-20T15:21:35.433Z
Updated: 2025-05-26T05:23:19.890Z
Reserved: 2025-04-16T04:51:23.965Z
Link: CVE-2025-37900
No data.
Status : Analyzed
Published: 2025-05-20T16:15:26.357
Modified: 2025-11-19T14:43:49.780
Link: CVE-2025-37900