Wiz Agents & Workflows are here

CVE-2025-38425
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38425 is a vulnerability discovered in the Linux kernel's I2C Tegra driver, specifically related to SMBUS block read operations. The vulnerability was disclosed on July 25, 2025, affecting various Linux kernel versions. The issue involves improper message length validation during SMBUS block read operations (NVD, Red Hat).

Technical details

The vulnerability exists in the I2C Tegra driver where the SMBUS block read operation fails to properly validate message lengths. Specifically, the driver continues reading even when the message length passed from the device is either '0' or exceeds the maximum allowed bytes. The vulnerability has been assigned a CVSS 3.1 base score of 7.0 with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a high severity issue requiring local access (Red Hat).

Impact

The vulnerability has been rated as having high severity impacts on confidentiality, integrity, and availability when successfully exploited. The issue affects multiple Linux distributions and versions, particularly impacting Red Hat Enterprise Linux 9 and 10, while earlier versions 6, 7, and 8 are not affected (Red Hat).

Mitigation and workarounds

A fix has been implemented in the Linux kernel to address this vulnerability by adding proper message length validation for SMBUS block read operations. The patch ensures that reading operations are halted if the message length is '0' or exceeds the maximum allowed bytes (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23395CRITICAL9.1
  • Linux KernelLinux Kernel
  • linux-xilinx-zynqmp
NoYesMar 25, 2026
CVE-2026-23399MEDIUM6.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-devel-matched
NoYesMar 28, 2026
CVE-2026-23398MEDIUM6.5
  • Linux KernelLinux Kernel
  • kernel-abi-stablelists
NoYesMar 26, 2026
CVE-2026-23397MEDIUM4.4
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-core
NoYesMar 26, 2026
CVE-2026-31788N/AN/A
  • Linux KernelLinux Kernel
  • kernel-devel-matched
NoYesMar 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management