PT-2025-28001 · Linux+6 · Linux Kernel+6

Published

2025-07-04

·

Updated

2026-04-20

·

CVE-2025-38226

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.14.0-rc2-syzkaller-00039-g09fbf3d50205
Description: A bug was found in the Linux kernel, specifically in the media subsystem, where the composition size cannot be larger than the size of fmt cap rect. This issue was identified by syzkaller and is related to a vmalloc-out-of-bounds error in the tpg fill plane pattern and tpg fill plane buffer functions. The error occurs when the size of the composing exceeds the size of fmt cap rect.
Recommendations: For Linux kernel versions prior to 6.14.0-rc2-syzkaller-00039-g09fbf3d50205, consider updating to a newer version that includes the fix for this issue. As a temporary workaround, execute v4l2 rect map inside() even if has compose cap == 0 to prevent the composition size from exceeding the size of fmt cap rect.

Exploit

Fix

Memory Corruption

Out of bounds Read

Weakness Enumeration

Related Identifiers

AZL-64689
BDU:2025-13484
CVE-2025-38226
DLA-4327-1
DLA-4328-1
DSA-5973-1
ECHO-F313-9EA7-D7D6
MGASA-2025-0218
MGASA-2025-0219
OESA-2025-1878
OESA-2025-1879
OESA-2025-1880
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:02853-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:02969-1
SUSE-SU-2025:02996-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:03023-1
SUSE-SU-2025:20577-1
SUSE-SU-2025:20586-1
SUSE-SU-2025:20601-1
SUSE-SU-2025:20602-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02969-1
SUSE-SU-2025_02996-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
SUSE-SU-2025_03023-1
USN-7774-1
USN-7774-2
USN-7774-3
USN-7774-4
USN-7774-5
USN-7775-1
USN-7775-2
USN-7775-3
USN-7776-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu