CVE-2025-38528 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 bpf lib/vsprintf.c bpf_trace_printk fmt[] format string
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7. This affects the function bpf_trace_printk in the library lib/vsprintf.c of the component bpf. The manipulation of the argument fmt[] results in format string.
This vulnerability was named CVE-2025-38528. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.