CVE-2025-38679
Linux Linux, SIMATIC CN 4100, linux kernel
In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload bound check Currently, The event_seq_changed() handler processes a variable number of properties sent by the firmware. The number of properties is indicated by the firmware and used to iterate over the payload. However, the payload size is not being validated against the actual message length. This can lead to out-of-bounds memory access if the firmware provides a property count that exceeds the data available in the payload. Such a condition can result in kernel crashes or...
- CVSS
- 7.1
- EPSS
- 0.16% 5.65% percentile
- CISA KEV
- Not listed
- Published
- 2025.09.05