PT-2025-22833 · Scsir · Scsir
Published
2025-05-24
·
Updated
2026-01-30
·
CVE-2025-48756
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
scsir crate version 0.2.0
Description
The issue arises from an overflow in the
group number due to a potential mismatch between the expected number of bits by a hardware device, typically a small number such as 5 bits, and the actual value provided. This discrepancy can lead to unexpected behavior.Recommendations
For scsir crate version 0.2.0, consider implementing input validation to ensure the
group number does not exceed the expected number of bits, thereby preventing the overflow. Additionally, review the hardware device's documentation to understand its specific requirements for the group number and adjust the scsir crate accordingly to prevent mismatches. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scsir