CVE-2025-38676

HIGH

Linux Kernel 5.4.237-5.4.x - Out-of-bounds Write in ACPIID Command Line Parsing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-38676. PoCs published by 14mb1v45h.

AI-analyzed exploit summary This repository provides a safe, non-exploit PoC for CVE-2025-38676, a stack buffer overflow in Linux Kernel ≤ 6.17-rc2 (AMD IOMMU). It includes tools for info-gathering, safety checks, and a QEMU boot harness to test long kernel cmdline permutations in a controlled VM environment.

Description

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel cmdline While the kernel command line is considered trusted in most environments, avoid writing 1 byte past the end of "acpiid" if the "str" argument is maximum length.

Exploits (1)

nomisec WORKING POC 1 stars
by 14mb1v45h · poc
https://github.com/14mb1v45h/CVE-2025-38676

This repository provides a safe, non-exploit PoC for CVE-2025-38676, a stack buffer overflow in Linux Kernel ≤ 6.17-rc2 (AMD IOMMU). It includes tools for info-gathering, safety checks, and a QEMU boot harness to test long kernel cmdline permutations in a controlled VM environment.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Linux Kernel ≤ 6.17-rc2 (AMD IOMMU)
No auth needed
Prerequisites: QEMU, build-essential, gcc, make, cpio, busybox · A vulnerable kernel version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 28.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (26)
debian/debian_linux 11.0
Linux/Linux < 6.3
Linux/Linux 2ae19ac3ea82a5b87a81c10adbb497c9e58bdd60 - 9ff52d3af0ef286535749e14e3fe9eceb39a8349
Linux/Linux 5.10.175 - 5.10.241
Linux/Linux 5.10.241 - 5.10.*
Linux/Linux 5.15.103 - 5.15.190
Linux/Linux 5.15.190 - 5.15.*
Linux/Linux 5.4.237 - 5.5
Linux/Linux 5e97dc748d13fad582136ba0c8cec215c7aeeb17
Linux/Linux 6.1.149 - 6.1.*
... and 16 more
Published Aug 26, 2025
Tracked Since Feb 18, 2026