CVE-2025-48638

All FrameworksAndroidCWE-787CVE-2025-48638

CVE-2025-48638

State: PUBLISHED · Published: 2025-12-08 · Updated: 2026-02-26 · Assigner: google_android
Description
In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/48xxx/CVE-2025-48638.json