CVE-2025-38366

Source
https://cve.org/CVERecord?id=CVE-2025-38366
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38366.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-38366
Downstream
Published
2025-07-25T12:47:36.104Z
Modified
2026-04-02T12:47:56.915415Z
Summary
LoongArch: KVM: Check validity of "num_cpu" from user space
Details

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: KVM: Check validity of "num_cpu" from user space

The maximum supported cpu number is EIOINTCROUTEMAX_VCPUS about irqchip EIOINTC, here add validation about cpu number to avoid array pointer overflow.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38366.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1ad7efa552fd5cf4e8c49fea863c5c6a5dcf9f00
Fixed
a3293b4078ee93174f70f36d3ab7618554ce6ab6
Fixed
cc8d5b209e09d3b52bca1ffe00045876842d96ae

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38366.json"