PT-2025-18412 · Linux+6 · Linux Kernel+6
Published
2025-03-03
·
Updated
2026-04-20
·
CVE-2025-23158
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability has been resolved in the Linux kernel, specifically in the media: venus: hfi component. The issue arises when the firmware modifies the
qsize value to an invalid large value, resulting in an empty space larger than the actual available space. This leads to an out-of-bounds (OOB) write when new wr idx is not checked. The qsize represents the size of the shared queue between the driver and video firmware. To address this, a check has been added to ensure qsize is within the allocated size when reading and writing packets into the queue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu