CVE-2025-38068

Updated: 2025-12-28 03:44:13.988266

Description:

In the Linux kernel, the following vulnerability has been resolved: crypto: lzo - Fix compression buffer overrun Unlike the decompression code, the compression code in LZO never checked for output overruns. It instead assumes that the caller always provides enough buffer space, disregarding the buffer length provided by the caller. Add a safe compression interface that checks for the end of buffer before each write. Use the safe interface in crypto/lzo.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Needs Triage 2025-12-28 08:46:25
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Needs Triage 2025-12-28 08:46:16
CentOS 7 ELS kernel 3.10.0 7.8 HIGH In Testing 2026-01-06 15:41:46
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Needs Triage 2025-12-28 08:46:19
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Needs Triage 2025-12-28 08:46:18
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Needs Triage 2025-12-28 08:46:29
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Needs Triage 2025-12-28 08:46:32
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Needs Triage 2025-12-28 08:46:27
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2026:1767867153 2026-01-08 16:23:06
Oracle Linux 7 ELS kernel-uek 5.4.17 7.8 HIGH Needs Triage 2025-12-28 07:00:48
Total: 16