CVE-2025-8412: A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registr
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registry to affect the integrity of the driver. We're not aware of a feasible way to exploit this currently.
This issue affects Virtual Machine Driver Pack: before e7a602ec232756ead019bdf19d6d3b9d010cc94b.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-8412
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-84120.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-8412 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for A Buffer Copy
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-67822: Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wi…nvd · 2026-07-31
- highCVE-2026-15722: A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruveleme…nvd · 2026-07-31
- mediumCVE-2026-33930: Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a b…nvd · 2026-07-29
- highCVE-2026-45811: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache…nvd · 2026-07-24
- criticalCVE-2026-64609: Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserializat…nvd · 2026-07-21
- mediumCVE-2026-16277: A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote r…nvd · 2026-07-20
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01