PT-2025-22833 · Scsir · Scsir

Published

2025-05-24

·

Updated

2026-01-30

·

CVE-2025-48756

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions scsir crate version 0.2.0
Description The issue arises from an overflow in the group number due to a potential mismatch between the expected number of bits by a hardware device, typically a small number such as 5 bits, and the actual value provided. This discrepancy can lead to unexpected behavior.
Recommendations For scsir crate version 0.2.0, consider implementing input validation to ensure the group number does not exceed the expected number of bits, thereby preventing the overflow. Additionally, review the hardware device's documentation to understand its specific requirements for the group number and adjust the scsir crate accordingly to prevent mismatches. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Type Confusion

Weakness Enumeration

Related Identifiers

CVE-2025-48756
GHSA-CM3G-QM4H-XM6M

Affected Products

Scsir