CVE-2025-38226

Kernel memory corruption via oversized composition rectangle

Published Jul 4, 2025 · Updated Aug 5, 2026

Out-of-bounds write in the Linux kernel vivid driver allows local users to corrupt kernel memory through crafted V4L2 ioctls. The driver preserves an oversized compose_cap rectangle when composing is disabled, then uses its stale dimensions in tpg_fill_plane_buffer to copy past the allocated vb2 frame buffer. Access to the vivid /dev/videoN node is required; the deterministic ioctl sequence can disclose or corrupt kernel memory and trigger a kernel panic.

CVSS severity7.8
High
EPSS probability0.17%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Out-of-bounds write in the Linux kernel vivid driver allows local users to corrupt kernel memory through crafted V4L2 ioctls. The driver preserves an oversized compose_cap rectangle when composing is disabled, then uses its stale dimensions in tpg_fill_plane_buffer to copy past the allocated vb2 frame buffer. Access to the vivid /dev/videoN node is required; the deterministic ioctl sequence can disclose or corrupt kernel memory and trigger a kernel panic.

The record

CVE
CVE-2025-38226
Published
Jul 4, 2025
Updated
Aug 5, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-787, T1068
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Jul 4, 2025CVE publishedPublication date reported by the CVE source.
  2. Aug 5, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=2f558c5208b0f70c8140e08ce09fcc84da48e789 <5d89aa42534723400fefd46e26e053b9c382b4ee
  2. Affected versionversion=4.14.303 <4.15
  3. Affected versionversion=4.19.270 <4.20
  4. Affected versionversion=4.9.337 <4.10
  5. Affected versionversion=5.10.163 <5.10.239
  6. Affected versionversion=5.15.86 <5.15.186
  7. Affected versionversion=5.4.229 <5.4.296
  8. Affected versionversion=54f259906039dbfe46c550011409fa16f72370f6 <57597d8db5bbda618ba2145b7e8a7e6f01b6a27e
  9. Affected versionversion=5edc3604151919da8da0fb092b71d7dce07d848a
  10. Affected versionversion=6.0.16 <6.1
  11. Affected versionversion=6.1.2 <6.1.142
  12. Affected versionversion=6.2
  13. Affected versionversion=8c0ee15d9a102c732d0745566d254040085d5663
  14. Affected versionversion=94a7ad9283464b75b12516c5512541d467cefcf8 <00da1c767a6567e56f23dda586847586868ac064
  15. Affected versionversion=94a7ad9283464b75b12516c5512541d467cefcf8 <c56398885716d97ee9bcadb2bc9663a8c1757a34
  16. Affected versionversion=94a7ad9283464b75b12516c5512541d467cefcf8 <f6b1b0f8ba0b61d8b511df5649d57235f230c135
  17. Affected versionversion=94a7ad9283464b75b12516c5512541d467cefcf8 <f83ac8d30c43fd902af7c84c480f216157b60ef0
  18. Affected versionversion=9c7fba9503b826f0c061d136f8f0c9f953ed18b9
  19. Affected versionversion=ab54081a2843aefb837812fac5488cc8f1696142 <89b5ab822bf69867c3951dd0eb34b0314c38966b
  20. Affected versionversion=ccb5392c4fea0e7d9f7ab35567e839d74cb3998b
  21. Affected versionversion=f9d19f3a044ca651b0be52a4bf951ffe74259b9f <635cea4f44c1ddae208666772c164eab5a6bce39

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=2f558c5208b0f70c8140e08ce09fcc84da48e789 <5d89aa42534723400fefd46e26e053b9c382b4ee; version=4.14.303 <4.15; version=4.19.270 <4.20; version=4.9.337 <4.10; version=5.10.163 <5.10.239; version=5.15.86 <5.15.186; version=5.4.229 <5.4.296; version=54f259906039dbfe46c550011409fa16f72370f6 <57597d8db5bbda618ba2145b7e8a7e6f01b6a27e; version=5edc3604151919da8da0fb092b71d7dce07d848a; version=6.0.16 <6.1; version=6.1.2 <6.1.142; version=6.2; version=8c0ee15d9a102c732d0745566d254040085d5663; version=94a7ad9283464b75b12516c5512541d467cefcf8 <00da1c767a6567e56f23dda586847586868ac064; version=94a7ad9283464b75b12516c5512541d467cefcf8 <c56398885716d97ee9bcadb2bc9663a8c1757a34; version=94a7ad9283464b75b12516c5512541d467cefcf8 <f6b1b0f8ba0b61d8b511df5649d57235f230c135; version=94a7ad9283464b75b12516c5512541d467cefcf8 <f83ac8d30c43fd902af7c84c480f216157b60ef0; version=9c7fba9503b826f0c061d136f8f0c9f953ed18b9; version=ab54081a2843aefb837812fac5488cc8f1696142 <89b5ab822bf69867c3951dd0eb34b0314c38966b; version=ccb5392c4fea0e7d9f7ab35567e839d74cb3998b; version=f9d19f3a044ca651b0be52a4bf951ffe74259b9f <635cea4f44c1ddae208666772c164eab5a6bce39

Published CVSS scores

5.5Amazon LinuxCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
7.8UbuntuCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8Linux Kernel CVE TeamCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-787Out-of-bounds Write
T1068Exploitation for Privilege Escalation

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo