CVE-2025-39815

MEDIUM

Linux Kernel - Stack Overflow in RISC-V KVM vlenb Loading

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb The userspace load can put up to 2048 bits into an xlen bit stack buffer. We want only xlen bits, so check the size beforehand.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (12)
linux/Kernel 6.13.0 - 6.16.5linux
linux/Kernel 6.8.0 - 6.12.45linux
Linux/Linux < 6.8
Linux/Linux 2fa290372dfe7dd248b1c16f943f273a3e674f22 - 6d28659b692a0212f360f8bd8a58712b339f9aac
Linux/Linux 2fa290372dfe7dd248b1c16f943f273a3e674f22 - 799766208f09f95677a9ab111b93872d414fbad7
Linux/Linux 2fa290372dfe7dd248b1c16f943f273a3e674f22 - c76bf8359188a11f8fd790e5bbd6077894a245cc
Linux/Linux 6.12.45 - 6.12.*
Linux/Linux 6.16.5 - 6.16.*
Linux/Linux 6.17
Linux/Linux 6.8
... and 2 more
Published Sep 16, 2025
Tracked Since Feb 18, 2026