CVE-2025-39815 (GCVE-0-2025-39815)
Vulnerability from cvelistv5
Published
2025-09-16 13:00
Modified
2026-08-05 12:05
Summary
In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb The userspace load can put up to 2048 bits into an xlen bit stack buffer. We want only xlen bits, so check the size beforehand.
Impacted products
Vendor Product Version
Linux Linux Version: 2fa290372dfe7dd248b1c16f943f273a3e674f22
Version: 2fa290372dfe7dd248b1c16f943f273a3e674f22
Version: 2fa290372dfe7dd248b1c16f943f273a3e674f22
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 5.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2025-39815",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-01-14T18:15:40.818434Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-01-14T18:22:55.580Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "arch/riscv/kvm/vcpu_vector.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "c76bf8359188a11f8fd790e5bbd6077894a245cc",
              "status": "affected",
              "version": "2fa290372dfe7dd248b1c16f943f273a3e674f22",
              "versionType": "git"
            },
            {
              "lessThan": "6d28659b692a0212f360f8bd8a58712b339f9aac",
              "status": "affected",
              "version": "2fa290372dfe7dd248b1c16f943f273a3e674f22",
              "versionType": "git"
            },
            {
              "lessThan": "799766208f09f95677a9ab111b93872d414fbad7",
              "status": "affected",
              "version": "2fa290372dfe7dd248b1c16f943f273a3e674f22",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "arch/riscv/kvm/vcpu_vector.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "lessThan": "6.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.45",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.16.*",
              "status": "unaffected",
              "version": "6.16.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.17",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.45",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16.5",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17",
                  "versionStartIncluding": "6.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRISC-V: KVM: fix stack overrun when loading vlenb\n\nThe userspace load can put up to 2048 bits into an xlen bit stack\nbuffer.  We want only xlen bits, so check the size beforehand."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is reached only through the KVM_SET_ONE_REG ioctl on a vCPU file descriptor obtained from /dev/kvm, requiring local access to the host. There is no remote or adjacent-network path to kvm_riscv_vcpu_set_reg_vector().\nAC:L - A single deterministic ioctl with a crafted reg-\u003eid size field (bits 52-55) triggers the overrun every time, with the attacker choosing both the copy length and the overflowing data. No race, no memory-layout guessing, and no condition outside the attacker\u0027s control on an affected RISC-V host with the V extension.\nPR:L - No capable()/CAP_SYS_ADMIN check exists anywhere on the path \u2014 only opening /dev/kvm and creating a VM/vCPU, which unprivileged users in the kvm group and sandboxed VMM processes (QEMU, crosvm) routinely have. The confined VMM process itself is the natural attacker here.\nUI:N - The attacking process performs the ioctl entirely on its own; no victim action, mount, or file open is needed.\nS:U - The attacker is host userspace and the corrupted memory is the host kernel stack of its own task \u2014 the same security authority, i.e. standard kernel privilege escalation rather than a guest-to-host or IOMMU boundary crossing.\nC:H - The attacker-controlled stack smash overwrites saved registers, frame pointers and return addresses, which is a classic route to control-flow hijack and hence arbitrary kernel memory disclosure. Per kernel scoring guidance, memory corruption leverageable for info disclosure is High.\nI:H - This is an out-of-bounds kernel stack write of up to ~32 KB with fully attacker-chosen contents and length, directly overwriting return addresses and adjacent frames \u2014 an arbitrary-write/code-execution primitive.\nA:H - Even without exploitation, overrunning the 16 KB RISC-V kernel stack reliably corrupts the stack canary, return addresses, or the VMAP guard page, producing an immediate kernel panic that any user with /dev/kvm access can trigger at will."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:05:22.677Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c76bf8359188a11f8fd790e5bbd6077894a245cc"
        },
        {
          "url": "https://git.kernel.org/stable/c/6d28659b692a0212f360f8bd8a58712b339f9aac"
        },
        {
          "url": "https://git.kernel.org/stable/c/799766208f09f95677a9ab111b93872d414fbad7"
        }
      ],
      "title": "RISC-V: KVM: fix stack overrun when loading vlenb",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-39815",
    "datePublished": "2025-09-16T13:00:16.250Z",
    "dateReserved": "2025-04-16T07:20:57.138Z",
    "dateUpdated": "2026-08-05T12:05:22.677Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.5, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-39815\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-01-14T18:15:40.818434Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"CWE-noinfo Not enough information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-01-14T18:15:36.719Z\"}}], \"cna\": {\"title\": \"RISC-V: KVM: fix stack overrun when loading vlenb\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"2fa290372dfe7dd248b1c16f943f273a3e674f22\", \"lessThan\": \"c76bf8359188a11f8fd790e5bbd6077894a245cc\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2fa290372dfe7dd248b1c16f943f273a3e674f22\", \"lessThan\": \"6d28659b692a0212f360f8bd8a58712b339f9aac\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2fa290372dfe7dd248b1c16f943f273a3e674f22\", \"lessThan\": \"799766208f09f95677a9ab111b93872d414fbad7\", \"versionType\": \"git\"}], \"programFiles\": [\"arch/riscv/kvm/vcpu_vector.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.8\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.8\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.12.45\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.16.5\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.16.*\"}, {\"status\": \"unaffected\", \"version\": \"6.17\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"arch/riscv/kvm/vcpu_vector.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/c76bf8359188a11f8fd790e5bbd6077894a245cc\"}, {\"url\": \"https://git.kernel.org/stable/c/6d28659b692a0212f360f8bd8a58712b339f9aac\"}, {\"url\": \"https://git.kernel.org/stable/c/799766208f09f95677a9ab111b93872d414fbad7\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nRISC-V: KVM: fix stack overrun when loading vlenb\\n\\nThe userspace load can put up to 2048 bits into an xlen bit stack\\nbuffer.  We want only xlen bits, so check the size beforehand.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.45\", \"versionStartIncluding\": \"6.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.16.5\", \"versionStartIncluding\": \"6.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.17\", \"versionStartIncluding\": \"6.8\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-07-30T05:57:47.288Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-39815\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-07-30T05:57:47.288Z\", \"dateReserved\": \"2025-04-16T07:20:57.138Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2025-09-16T13:00:16.250Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…