CVE-2025-38497 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 usb os_desc_qw_sign_store out-of-bounds (Nessus ID 253428 / WID-SEC-2025-1665)
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7. The affected element is the function os_desc_qw_sign_store of the component usb. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2025-38497. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.