PT-2025-29052 · Linux+4 · Linux Kernel+4

Published

2025-07-10

·

Updated

2026-04-20

·

CVE-2025-38330

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains a flaw in the cs dsp firmware related to out-of-bounds memory access during a KUnit test (ctl cache). The issue occurs in the cs dsp ctl cache init multiple offsets() function, where the length of a register value allocation is incorrectly overridden, leading to test failures. The fix removes the length override, maintaining the original value of 4 for all operations.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-10742
CVE-2025-38330
ECHO-AA70-B370-E72C
RHSA-2025:20095
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Ubuntu