{"id":"DEBIAN-CVE-2025-38493","details":"In the Linux kernel, the following vulnerability has been resolved:  tracing/osnoise: Fix crash in timerlat_dump_stack()  We have observed kernel panics when using timerlat with stack saving, with the following dmesg output:  memcpy: detected buffer overflow: 88 byte write of buffer size 0 WARNING: CPU: 2 PID: 8153 at lib/string_helpers.c:1032 __fortify_report+0x55/0xa0 CPU: 2 UID: 0 PID: 8153 Comm: timerlatu/2 Kdump: loaded Not tainted 6.15.3-200.fc42.x86_64 #1 PREEMPT(lazy) Call Trace:  \u003cTASK\u003e  ? trace_buffer_lock_reserve+0x2a/0x60  __fortify_panic+0xd/0xf  __timerlat_dump_stack.cold+0xd/0xd  timerlat_dump_stack.part.0+0x47/0x80  timerlat_fd_read+0x36d/0x390  vfs_read+0xe2/0x390  ? syscall_exit_to_user_mode+0x1d5/0x210  ksys_read+0x73/0xe0  do_syscall_64+0x7b/0x160  ? exc_page_fault+0x7e/0x1a0  entry_SYSCALL_64_after_hwframe+0x76/0x7e  __timerlat_dump_stack() constructs the ftrace stack entry like this:  struct stack_entry *entry; ... memcpy(&entry-\u003ecaller, fstack-\u003ecalls, size); entry-\u003esize = fstack-\u003enr_entries;  Since commit e7186af7fb26 (\"tracing: Add back FORTIFY_SOURCE logic to kernel_stack event structure\"), struct stack_entry marks its caller field with __counted_by(size). At the time of the memcpy, entry-\u003esize contains garbage from the ringbuffer, which under some circumstances is zero, triggering a kernel panic by buffer overflow.  Populate the size field before the memcpy so that the out-of-bounds check knows the correct size. This is analogous to __ftrace_trace_stack().","modified":"2026-08-27T23:05:30.102192067Z","published":"2025-07-28T12:15:31.483Z","upstream":["CVE-2025-38493"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38493"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.41-1"}]}],"versions":["6.12.38-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38493.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.16.3-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.3-1~bpo13+1","6.16~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38493.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}