PT-2025-22240 · Linux+5 · Linux Kernel+5
Published
2025-04-01
·
Updated
2026-04-20
·
CVE-2025-37979
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A potential buffer overflow issue has been identified in the Linux kernel, specifically in the ASoC qcom sc7280 lpass driver. This issue arises from case values introduced in a commit, causing out of bounds access in arrays of sc7280 driver data. For example, this can occur in the
sc7280 snd hw params() function when handling RX CODEC DMA RX 0. The issue was found by the Linux Verification Center with SVACE. To address this, the LPASS MAX PORTS value has been redefined to account for the maximum possible port id for q6dsp, as utilized by the sc7280 driver.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu