
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38366 is a vulnerability discovered in the Linux kernel, specifically affecting the LoongArch KVM implementation. The vulnerability was disclosed on July 25, 2025, and involves improper validation of the 'num_cpu' parameter from user space in relation to the EIOINTC irqchip (NVD, RedHat).
The vulnerability stems from insufficient validation of the 'numcpu' parameter in the LoongArch KVM implementation. The issue relates to the maximum supported CPU number defined by EIOINTCROUTEMAXVCPUS for the EIOINTC irqchip. The CVSS v3.1 base score is 5.5 with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local attack vector with low complexity requirements (RedHat).
The vulnerability could lead to array pointer overflow conditions when handling CPU numbers in the KVM virtualization environment. This primarily affects the availability aspect of the system, as indicated by the CVSS metrics showing high impact on availability but no impact on confidentiality or integrity (RedHat).
A fix has been implemented that adds validation for the CPU number to prevent array pointer overflow. The vulnerability has been resolved in the Linux kernel through proper validation of the 'numcpu' parameter against the EIOINTCROUTEMAXVCPUS limit (NVD, Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."