CVE-2025-38649 | Linux Kernel up to 6.15.9/6.16.0 arm64 coresight_find_activated_sysfs_sink stack-based overflow (Nessus ID 276629 / WID-SEC-2025-1898)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.15.9/6.16.0. Impacted is the function coresight_find_activated_sysfs_sink of the component arm64. The manipulation results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2025-38649. The attack must originate from the local network. There is no exploit available.
It is advisable to upgrade the affected component.