CVE-2025-48638
In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
More information : https://android.googlesource.com/kernel/common/+/0429b7af308cf65c84109c08d06b01950dcd57fe
