CVE-2025-38676

Kernel memory corruption via oversized ACPI identifier

Published Aug 26, 2025 · Updated May 23, 2026

Stack-based buffer overflow in the Linux AMD IOMMU initializer allows local users to corrupt kernel memory via a crafted boot argument. The parse_ivrs_acpihid function accepts a maximum-length ACPI identifier, then sscanf writes its terminating null byte one byte past the acpiid stack buffer. Privileged control of the kernel command line before boot is required; SIMATIC CN 4100 before V5.0 inherits the same integrity and availability exposure.

CVSS severity6.0
Medium
EPSS probability0.40%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Stack-based buffer overflow in the Linux AMD IOMMU initializer allows local users to corrupt kernel memory via a crafted boot argument. The parse_ivrs_acpihid function accepts a maximum-length ACPI identifier, then sscanf writes its terminating null byte one byte past the acpiid stack buffer. Privileged control of the kernel command line before boot is required; SIMATIC CN 4100 before V5.0 inherits the same integrity and availability exposure.

The record

CVE
CVE-2025-38676
Published
Aug 26, 2025
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-805
Attack vector
local
Privileges
admin

Timeline

How it unfolded

  1. Aug 26, 2025CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=2ae19ac3ea82a5b87a81c10adbb497c9e58bdd60 <9ff52d3af0ef286535749e14e3fe9eceb39a8349
  2. Affected versionversion=5.10.175 <5.10.241
  3. Affected versionversion=5.15.103 <5.15.190
  4. Affected versionversion=5.4.237 <5.5
  5. Affected versionversion=5e97dc748d13fad582136ba0c8cec215c7aeeb17
  6. Affected versionversion=6.1.16 <6.1.149
  7. Affected versionversion=6.2.3 <6.3
  8. Affected versionversion=6.3
  9. Affected versionversion=63cd11165e5e0ea2012254c764003eda1f9adb7d
  10. Affected versionversion=b6b26d86c61c441144c72f842f7469bb686e1211 <4bdb0f78bddbfa77d3ab458a21dd9cec495d317a
  11. Affected versionversion=b6b26d86c61c441144c72f842f7469bb686e1211 <736db11c86f03e717fc4bf771d05efdf10d23acb
  12. Affected versionversion=b6b26d86c61c441144c72f842f7469bb686e1211 <8503d0fcb1086a7cfe26df67ca4bd9bd9e99bdec
  13. Affected versionversion=b6b26d86c61c441144c72f842f7469bb686e1211 <8f80c633cba144f721d38d9380f23d23ab7db10e
  14. Affected versionversion=c513043e0afe6a8ba79d00af358655afabb576d2 <0ad8509b468fa1058f4f400a1829f29e4ccc4de8
  15. Affected versionversion=f2a5ec7f7b28f9b9cd5fac232ff51019a7f7b9e9 <a732502bf3bbe859613b6d7b2b0313b11f0474ac

What conditions does exploitation require?

Attack vectorlocal
Required privilegesadmin

What is affected?

The Linux Kernel Organization · Linuxversion=2ae19ac3ea82a5b87a81c10adbb497c9e58bdd60 <9ff52d3af0ef286535749e14e3fe9eceb39a8349; version=5.10.175 <5.10.241; version=5.15.103 <5.15.190; version=5.4.237 <5.5; version=5e97dc748d13fad582136ba0c8cec215c7aeeb17; version=6.1.16 <6.1.149; version=6.2.3 <6.3; version=6.3; version=63cd11165e5e0ea2012254c764003eda1f9adb7d; version=b6b26d86c61c441144c72f842f7469bb686e1211 <4bdb0f78bddbfa77d3ab458a21dd9cec495d317a; version=b6b26d86c61c441144c72f842f7469bb686e1211 <736db11c86f03e717fc4bf771d05efdf10d23acb; version=b6b26d86c61c441144c72f842f7469bb686e1211 <8503d0fcb1086a7cfe26df67ca4bd9bd9e99bdec; version=b6b26d86c61c441144c72f842f7469bb686e1211 <8f80c633cba144f721d38d9380f23d23ab7db10e; version=c513043e0afe6a8ba79d00af358655afabb576d2 <0ad8509b468fa1058f4f400a1829f29e4ccc4de8; version=f2a5ec7f7b28f9b9cd5fac232ff51019a7f7b9e9 <a732502bf3bbe859613b6d7b2b0313b11f0474ac
Siemens · SIMATIC CN 4100version=0 <V5.0

Published CVSS scores

6.0Siemens ProductCERTCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
7.8NIST NVDCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesadmin
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-805Buffer Access with Incorrect Length Value

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo