Reading the CVSS 7.1 Score for CVE-2025-38680: Local, Low Complexity, High Confidentiality Impact
Reading the CVSS 7.1 Score for CVE-2025-38680: Local, Low Complexity, High Confidentiality Impact Vulnerability overview CVE-2025-38680 is a Linux kernel out-of-bounds read in the USB Video Class driver, in uvc_parse_format() . NVD scores it 7.1 with base severity HIGH under CVSS 3.1, using the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H . This article takes the vector apart, because each…
CVE-2025-38680 is a vulnerability affecting the Linux kernel due to an out-of-bounds read in the USB Video Class driver. The National Vulnerability Database (NVD) assigns a high severity score of 7.1 based on the Common Vulnerability Scoring System (CVSS) 3.1. This score is derived from several factors including the attack vector, complexity, privileges required, and the impact on confidentiality, availability, and integrity.
The vulnerability allows an attacker to read past the intended buffer in the read function, specifically buffer[3] after a guard condition that checks buflen >= 2. This means that a local attacker with access to the host device interface can exploit the vulnerability without needing to meet any complex requirements. The attack complexity is low (AC:L), as no special conditions or configurations are necessary to execute the exploit.
Additionally, the privileges required to carry out the attack are also low (PR:L), meaning that an attacker does not need elevated access to perform the exploit.
The confidentiality impact of this vulnerability is high (C:H) because it involves a memory disclosure primitive, which can expose sensitive information. It also has a high impact on availability (A:H), as the kernel fault caused by the read operation can lead to system crashes. Integrity is not affected in this case (I:N), as the vulnerability involves a read operation rather than a write operation, and no data is modified.
The CVSS score for this vulnerability is 7.1, indicating a high severity level. It is important to note that while the score reflects the potential impact of the vulnerability, it does not guarantee the existence of a working exploit or a complete privilege escalation chain. Affected products include Linux kernel versions 2.6.26 and later, with specific fixes available in versions 5.4.297, 5.10.241, 5.15.190, 6.1.149, 6.6.103, 6.12.43, 6.15.11, and 6.16.2. The vulnerability has been confirmed in platforms such as Debian 11.
The exposure context shows that no assets were indexed against this CVE by ZoomEye, but the product probe reported 14 instances of Linux Kernel and 18,182,408 Linux hosts. These statistics provide a broader view of the potential reach of the vulnerability within affected systems. To mitigate the risk, it is recommended to apply the patched kernel version for the specific branch and reboot the system. If the camera subsystem is not in use, disabling or unloading the driver can eliminate the vulnerability entirely.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.