PT-2026-2904 · Samsung+3 · Samsung Exynos+3

Published

2025-01-01

·

Updated

2026-05-11

·

CVE-2025-71143

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Samsung Exynos clock output driver within the Linux kernel. A bounds sanitizer warning occurs because the .num member of struct clk hw onecell data is assigned after accessing the .hws array. This can lead to out-of-bounds access when the .hws array is accessed before initialization, resulting in a warning. The issue is related to the initialization order of the .num field, which tracks the number of elements in the .hws array.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Improper Initialization

Weakness Enumeration

Related Identifiers

BDU:2026-01569
CVE-2025-71143
MGASA-2026-0017
MGASA-2026-0018
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
USN-8177-1
USN-8177-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8183-1
USN-8183-2
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8245-1
USN-8257-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1

Affected Products

Linuxmint
Linux Kernel
Samsung Exynos
Ubuntu