CVE Database
/

CVE-2025-23159

Back to search

CVE-2025-23159

Published: May 1, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than actual sfr data buffer. Cap the size to allocated size for such cases.

VendorProductVersions

Linux

Linux

affected
d96d3f30c0f2f564f6922bf4ccdf4464992e31fb - < 4dd109038d513b92d4d33524ffc89ba32e02ba48
affected
d96d3f30c0f2f564f6922bf4ccdf4464992e31fb - < 8879397c0da5e5ec1515262995e82cdfd61b282a
affected
d96d3f30c0f2f564f6922bf4ccdf4464992e31fb - < 1b8fb257234e7d2d4b3f48af07c5aa5e11c71634
affected
d96d3f30c0f2f564f6922bf4ccdf4464992e31fb - < 4e95233af57715d81830fe82b408c633edff59f4
affected
d96d3f30c0f2f564f6922bf4ccdf4464992e31fb - < 5af611c70fb889d46d2f654b8996746e59556750

+4 more versions

Linux

Linux

affected
4.13
unaffected
0 - < 4.13
unaffected
5.4.293 - <= 5.4.*
unaffected
5.10.237 - <= 5.10.*
unaffected
5.15.181 - <= 5.15.*

+6 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now