{
  "id": 13029389,
  "title": "Reading the CVSS 7.1 Score for CVE-2025-38680: Local, Low Complexity, High Confidentiality Impact",
  "url": "https://urgent.news/2026/10/09/reading-the-cvss-7-1-score-for-cve-2025-38680-local-low-complexity",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T04:40:39.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/onaeiuspkz/reading-the-cvss-71-score-for-cve-2025-38680-local-low-complexity-high-confidentiality-impact-36h9"
  },
  "original_language": "en",
  "account": "CVE-2025-38680 is a vulnerability affecting the Linux kernel due to an out-of-bounds read in the USB Video Class driver. The National Vulnerability Database (NVD) assigns a high severity score of 7.1 based on the Common Vulnerability Scoring System (CVSS) 3.1. This score is derived from several factors including the attack vector, complexity, privileges required, and the impact on confidentiality, availability, and integrity.\n\nThe vulnerability allows an attacker to read past the intended buffer in the read function, specifically buffer[3] after a guard condition that checks buflen >= 2. This means that a local attacker with access to the host device interface can exploit the vulnerability without needing to meet any complex requirements. The attack complexity is low (AC:L), as no special conditions or configurations are necessary to execute the exploit. Additionally, the privileges required to carry out the attack are also low (PR:L), meaning that an attacker does not need elevated access to perform the exploit.\n\nThe confidentiality impact of this vulnerability is high (C:H) because it involves a memory disclosure primitive, which can expose sensitive information. It also has a high impact on availability (A:H), as the kernel fault caused by the read operation can lead to system crashes. Integrity is not affected in this case (I:N), as the vulnerability involves a read operation rather than a write operation, and no data is modified.\n\nThe CVSS score for this vulnerability is 7.1, indicating a high severity level. It is important to note that while the score reflects the potential impact of the vulnerability, it does not guarantee the existence of a working exploit or a complete privilege escalation chain. Affected products include Linux kernel versions 2.6.26 and later, with specific fixes available in versions 5.4.297, 5.10.241, 5.15.190, 6.1.149, 6.6.103, 6.12.43, 6.15.11, and 6.16.2. The vulnerability has been confirmed in platforms such as Debian 11.\n\nThe exposure context shows that no assets were indexed against this CVE by ZoomEye, but the product probe reported 14 instances of Linux Kernel and 18,182,408 Linux hosts. These statistics provide a broader view of the potential reach of the vulnerability within affected systems. To mitigate the risk, it is recommended to apply the patched kernel version for the specific branch and reboot the system. If the camera subsystem is not in use, disabling or unloading the driver can eliminate the vulnerability entirely.",
  "summary": "Reading the CVSS 7.1 Score for CVE-2025-38680: Local, Low Complexity, High Confidentiality Impact Vulnerability overview CVE-2025-38680 is a Linux kernel out-of-bounds read in the USB Video Class driver, in uvc_parse_format() . NVD scores it 7.1 with base severity HIGH under CVSS 3.1, using the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H . This article takes the vector apart, because each…",
  "key_points": [
    "CVE-2025-38680 affects Linux kernel due to out-of-bounds read in USB Video Class driver.",
    "NVD assigns high severity score of 7.1 based on CVSS 3.1.",
    "Local attacker can exploit vulnerability with low attack complexity and privileges."
  ],
  "editors_take": "This vulnerability's high severity score reflects its potential for local attackers with low privileges to exploit it with low complexity and expose sensitive information, impacting confidentiality and availability.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}