CVE-2025-52568
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
24/06/2025
Last modified:
26/06/2025
Description
NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory corruption, disk image corruption, denial of service, and potential code execution. These issues stem from unchecked memory operations, unsafe typecasting, and improper input validation. This issue has been patched in version 0.0.3.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/nekernel-org/nekernel/commit/6506875ad0ab210b82a5c4ce227bf851508de17d
- https://github.com/nekernel-org/nekernel/commit/6511afbf405c31513bc88ab06bca58218610a994
- https://github.com/nekernel-org/nekernel/pull/35
- https://github.com/nekernel-org/nekernel/pull/36
- https://github.com/nekernel-org/nekernel/security/advisories/GHSA-cmp2-5f6g-mw34