DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

Reading the CVSS 7.1 Score for CVE-2025-38680: Local, Low Complexity, High Confidentiality Impact

Reading the CVSS 7.1 Score for CVE-2025-38680: Local, Low Complexity, High Confidentiality Impact

Vulnerability overview

CVE-2025-38680 is a Linux kernel out-of-bounds read in the USB Video Class driver, in uvc_parse_format(). NVD scores it 7.1 with base severity HIGH under CVSS 3.1, using the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H. This article takes the vector apart, because each metric changes what an operator should do.

Mechanism and exploitation conditions

The function read buffer[3] after a guard that only required buflen > 2, so a three-byte buffer yields a one-byte read past its end. CVSS describes that situation as AC:L, low attack complexity: no race, no unusual configuration and no specialised preparation appear in the record.
AV:L records a local attack vector. The parsing path is reached through a USB video device, so the attacker needs presence on or access to the host's device interface rather than a routable network position. PR:L means low privileges are sufficient. UI:N means no separate user has to be persuaded to act.

Impact

The vector's impact metrics are the interesting part. Confidentiality is HIGH, matching a memory-disclosure primitive. Availability is HIGH as well, which is consistent with a kernel fault that can take the machine down. Integrity is NONE: the record describes a read, not a write, so nothing is modified. S:U keeps the scope unchanged.
Reading these together gives a fair summary: a locally reachable, low-complexity kernel memory read that can crash the affected system. The record does not describe a working exploit or a complete privilege-escalation chain, so the score should not be read as a promise of one.

Affected products and scope

The introducing commit is c0efd232929c2cd87238de2cccdaf4e845be5b0c. The CNA marks 2.6.26 and later as affected and lists fixes at 5.4.297, 5.10.241, 5.15.190, 6.1.149, 6.6.103, 6.12.43, 6.15.11 and 6.16.2; NVD's CPE ranges start at 2.6.27. Debian 11 is named as an affected platform.

Exposure context

ZoomEye indexes no assets against this CVE, so vul.cve="CVE-2025-38680" returned 0. The product probe app="Linux Kernel" returned 14 and os="Linux" && port="22" returned 18,182,408. A CVSS score is a property of the flaw, not of your fleet; these figures size reachable Linux hosts, not vulnerable kernels.

Remediation and mitigations

Apply the fixed kernel for your branch and reboot. Because availability impact is rated HIGH, treat unpatched hosts as crash-prone rather than merely leaky. Where the camera subsystem is unused, unloading or disabling the driver removes the path entirely.

References

Top comments (0)