CVE-2025-38257

s390/pkey: Prevent overflow in size calculation for memdup_user()

References

Notes

 carnil> Introduced in f2bbc96e7cfa ("s390/pkey: add CCA AES cipher key support").
 carnil> Vulnerable versions: 5.4.

Bugs

Status

Branch Status
upstream released (6.16-rc4) [7360ee47599af91a1d5f4e74d635d9408a54e489]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.15-upstream-stable released (6.15.5) [73483ca7e07a5e39bdf612eec9d3d293e8bef649]
6.12-upstream-stable released (6.12.36) [f855b119e62b004a5044ed565f2a2b368c4d3f16]
6.6-upstream-stable released (6.6.96) [88f3869649edbc4a13f6c2877091f81cd5a50f05]
6.1-upstream-stable released (6.1.143) [faa1ab4a23c42e34dc000ef4977b751d94d5148c]
5.10-upstream-stable needed
sid released (6.12.37-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.147-1)
5.10-bullseye-security needed