PT-2025-22240 · Linux+5 · Linux Kernel+5

Published

2025-04-01

·

Updated

2026-04-20

·

CVE-2025-37979

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential buffer overflow issue has been identified in the Linux kernel, specifically in the ASoC qcom sc7280 lpass driver. This issue arises from case values introduced in a commit, causing out of bounds access in arrays of sc7280 driver data. For example, this can occur in the sc7280 snd hw params() function when handling RX CODEC DMA RX 0. The issue was found by the Linux Verification Center with SVACE. To address this, the LPASS MAX PORTS value has been redefined to account for the maximum possible port id for q6dsp, as utilized by the sc7280 driver.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-11836
CVE-2025-37979
DLA-4193-1
ECHO-AB7B-6C86-0D89
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu