Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      This week in AI dev tools: Gemini API Batch Mode, Amazon SageMaker AI updates, and more (July 11, 2025)

      July 11, 2025

      JFrog finds MCP-related vulnerability, highlighting need for stronger focus on security in MCP ecosystem

      July 11, 2025

      8 Key Questions Every CEO Should Ask Before Hiring a Node.js Development Company in 2025

      July 11, 2025

      Vibe Loop: AI-native reliability engineering for the real world

      July 10, 2025

      51% claimed already: This Xbox Edition mechanical keyboard is at its lowest price yet while this sale lasts — Nostalgic green transparency for the win

      July 11, 2025

      This RDR2 deal feels like highway robbery — grab the “Wild West masterpiece” today before it rides off into the sunset

      July 11, 2025

      Grab these 7 Xbox games all under $40 — you don’t have long before Amazon Prime Day ends, so act fast

      July 11, 2025

      After 24 hours with Samsung’s Galaxy Z Flip 7, one big thing stands out

      July 11, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The details of TC39’s last meeting

      July 11, 2025
      Recent

      The details of TC39’s last meeting

      July 11, 2025

      Francisco Bergeret Paves the Way Through Strong Leadership at Perficient

      July 11, 2025

      Intelligent Automation in the Healthcare Sector with n8n, OpenAI, and Pinecone

      July 11, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      51% claimed already: This Xbox Edition mechanical keyboard is at its lowest price yet while this sale lasts — Nostalgic green transparency for the win

      July 11, 2025
      Recent

      51% claimed already: This Xbox Edition mechanical keyboard is at its lowest price yet while this sale lasts — Nostalgic green transparency for the win

      July 11, 2025

      This RDR2 deal feels like highway robbery — grab the “Wild West masterpiece” today before it rides off into the sunset

      July 11, 2025

      Grab these 7 Xbox games all under $40 — you don’t have long before Amazon Prime Day ends, so act fast

      July 11, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-38345 – “Intel Virtual Box ACPICA Illegal I/O Port Address/Length Vulnerability”

    CVE-2025-38345 – “Intel Virtual Box ACPICA Illegal I/O Port Address/Length Vulnerability”

    July 10, 2025

    CVE ID : CVE-2025-38345

    Published : July 10, 2025, 9:15 a.m. | 4 hours, 51 minutes ago

    Description : In the Linux kernel, the following vulnerability has been resolved:

    ACPICA: fix acpi operand cache leak in dswstate.c

    ACPICA commit 987a3b5cf7175916e2a4b6ea5b8e70f830dfe732

    I found an ACPI cache leak in ACPI early termination and boot continuing case.

    When early termination occurs due to malicious ACPI table, Linux kernel
    terminates ACPI function and continues to boot process. While kernel terminates
    ACPI function, kmem_cache_destroy() reports Acpi-Operand cache leak.

    Boot log of ACPI operand cache leak is as follows:
    >[ 0.585957] ACPI: Added _OSI(Module Device)
    >[ 0.587218] ACPI: Added _OSI(Processor Device)
    >[ 0.588530] ACPI: Added _OSI(3.0 _SCP Extensions)
    >[ 0.589790] ACPI: Added _OSI(Processor Aggregator Device)
    >[ 0.591534] ACPI Error: Illegal I/O port address/length above 64K: C806E00000004002/0x2 (20170303/hwvalid-155)
    >[ 0.594351] ACPI Exception: AE_LIMIT, Unable to initialize fixed events (20170303/evevent-88)
    >[ 0.597858] ACPI: Unable to start the ACPI Interpreter
    >[ 0.599162] ACPI Error: Could not remove SCI handler (20170303/evmisc-281)
    >[ 0.601836] kmem_cache_destroy Acpi-Operand: Slab cache still has objects
    >[ 0.603556] CPU: 0 PID: 1 Comm: swapper/0 Not tainted 4.12.0-rc5 #26
    >[ 0.605159] Hardware name: innotek gmb_h virtual_box/virtual_box, BIOS virtual_box 12/01/2006
    >[ 0.609177] Call Trace:
    >[ 0.610063] ? dump_stack+0x5c/0x81
    >[ 0.611118] ? kmem_cache_destroy+0x1aa/0x1c0
    >[ 0.612632] ? acpi_sleep_proc_init+0x27/0x27
    >[ 0.613906] ? acpi_os_delete_cache+0xa/0x10
    >[ 0.617986] ? acpi_ut_delete_caches+0x3f/0x7b
    >[ 0.619293] ? acpi_terminate+0xa/0x14
    >[ 0.620394] ? acpi_init+0x2af/0x34f
    >[ 0.621616] ? __class_create+0x4c/0x80
    >[ 0.623412] ? video_setup+0x7f/0x7f
    >[ 0.624585] ? acpi_sleep_proc_init+0x27/0x27
    >[ 0.625861] ? do_one_initcall+0x4e/0x1a0
    >[ 0.627513] ? kernel_init_freeable+0x19e/0x21f
    >[ 0.628972] ? rest_init+0x80/0x80
    >[ 0.630043] ? kernel_init+0xa/0x100
    >[ 0.631084] ? ret_from_fork+0x25/0x30
    >[ 0.633343] vgaarb: loaded
    >[ 0.635036] EDAC MC: Ver: 3.0.0
    >[ 0.638601] PCI: Probing PCI hardware
    >[ 0.639833] PCI host bridge to bus 0000:00
    >[ 0.641031] pci_bus 0000:00: root bus resource [io 0x0000-0xffff]
    > … Continue to boot and log is omitted …

    I analyzed this memory leak in detail and found acpi_ds_obj_stack_pop_and_
    delete() function miscalculated the top of the stack. acpi_ds_obj_stack_push()
    function uses walk_state->operand_index for start position of the top, but
    acpi_ds_obj_stack_pop_and_delete() function considers index 0 for it.
    Therefore, this causes acpi operand memory leak.

    This cache leak causes a security threat because an old kernel (
    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-6948 – GitLab Cross-Site Scripting (XSS) Vulnerability
    Next Article CVE-2025-3396 – GitLab EE API Request Forgery Vulnerability

    Related Posts

    Development

    Critical Vulnerability in Anthropic’s MCP Exposes Developer Machines to Remote Exploits

    July 11, 2025
    Development

    Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials

    July 11, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Text Pieces is a developer’s scratchpad

    Linux

    CVE-2025-3824 – SourceCodester Web-based Pharmacy Product Management System Cross-Site Scripting Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-30171 – ASPECT System File Deletion Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2022-47111 – 7-Zip XZ File Format Parsing Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    CISA tags Broadcom Fabric OS, CommVault flaws as exploited in attacks

    April 29, 2025

    CISA tags Broadcom Fabric OS, CommVault flaws as exploited in attacks

    The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning of Broadcom Brocade Fabric OS, Commvault web servers, and Qualitia Active! Mail clients vulnerabilities that are actively expl …
    Read more

    Published Date:
    Apr 29, 2025 (2 hours, 31 minutes ago)

    Vulnerabilities has been mentioned in this article.

    CVE-2025-3928

    CVE-2025-1976

    CVE-2025-42599

    “So many amazing Forgers have just given up” — Halo Infinite just lost its best Forge creators over lack of support

    June 20, 2025

    Our vision for building a universal AI assistant

    May 20, 2025

    Apache SeaTunnel Vulnerability Allows Unauthorized Users to Perform Deserialization Attack

    June 20, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.