CVE-2025-38425

Updated: 2026-02-27 03:53:17.77068

Description:

In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: check msg length in SMBUS block read For SMBUS block read, do not continue to read if the message length passed from the device is '0' or greater than the maximum allowed bytes.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

RHEL 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-12-31 06:37:51 Not affected: CVE-2025-38425 targets the NVIDIA Tegra I2C controller driver (drivers/i2c/busses/i2c-...
TuxCare 9.6 ESU kernel 5.14.0 7.8 HIGH Already Fixed 2026-01-12 17:52:09
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Needs Triage 2025-12-28 07:15:07
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Needs Triage 2025-12-28 07:32:14
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Not Vulnerable 2025-12-31 06:49:01 Not affected: this CVE targets the NVIDIA Tegra I2C controller driver’s SMBus block‑read path (d...
Ubuntu 20.04 ELS linux 5.4.0 7.8 HIGH Not Vulnerable 2025-12-31 06:49:00 Not affected: this issue is limited to the NVIDIA Tegra I2C controller driver (i2c-tegra, CONFIG_I2C...
Total: 16