PT-2025-36275 · Linux · Linux Kernel

Published

2025-09-05

·

Updated

2025-09-06

·

CVE-2025-39680

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.

Name of the Vulnerable Software and Affected Versions:

Linux kernel (affected versions not specified)

Description:

The Linux kernel contains an out-of-bounds bug in the `rtl9300 i2c smbus xfer` function. The `data->block[0]` variable, sourced from user input, lacks proper validation, potentially leading to a buffer overflow. The issue is addressed by verifying the value of `data->block[0]` before use.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2025-39680

Affected Products

Linux Kernel