CVE-2025-37979

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
20/05/2025
Last modified:
16/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ASoC: qcom: Fix sc7280 lpass potential buffer overflow<br /> <br /> Case values introduced in commit<br /> 5f78e1fb7a3e ("ASoC: qcom: Add driver support for audioreach solution")<br /> cause out of bounds access in arrays of sc7280 driver data (e.g. in case<br /> of RX_CODEC_DMA_RX_0 in sc7280_snd_hw_params()).<br /> <br /> Redefine LPASS_MAX_PORTS to consider the maximum possible port id for<br /> q6dsp as sc7280 driver utilizes some of those values.<br /> <br /> Found by Linux Verification Center (linuxtesting.org) with SVACE.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.18 (including) 6.1.136 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.88 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.25 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.14.4 (excluding)
cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*