CVE-2025-38613
MEDIUMLinux Kernel 6.13-6.16.1 - Information Exposure via Uninitialized Memory in GPIB Board Info IOCTL
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: staging: gpib: fix unset padding field copy back to userspace The introduction of a padding field in the gpib_board_info_ioctl is showing up as initialized data on the stack frame being copyied back to userspace in function board_info_ioctl. The simplest fix is to initialize the entire struct to zero to ensure all unassigned padding fields are zero'd before being copied back to userspace.
References (2)
Core 2
Scores
CVSS v3
5.5
EPSS
0.0013
EPSS Percentile
2.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-908
Status
published
Products (8)
linux/Kernel
6.13.0 - 6.16.1linux
Linux/Linux
< 6.13
Linux/Linux
6.13
Linux/Linux
6.16.1 - 6.16.*
Linux/Linux
6.17
Linux/Linux
9dde4559e93955ccc47d588f7fd051684d55c4e7 - 19dedd4f70f5a6505e7c601ef7dd40542d1d9aa5
Linux/Linux
9dde4559e93955ccc47d588f7fd051684d55c4e7 - a739d3b13bff0dfa1aec679d08c7062131a2a425
linux/linux_kernel
6.13 - 6.16.1
Published
Aug 19, 2025
Tracked Since
Feb 18, 2026