CVE-2025-38380

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2025
Last modified:
25/07/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> i2c/designware: Fix an initialization issue<br /> <br /> The i2c_dw_xfer_init() function requires msgs and msg_write_idx from the<br /> dev context to be initialized.<br /> <br /> amd_i2c_dw_xfer_quirk() inits msgs and msgs_num, but not msg_write_idx.<br /> <br /> This could allow an out of bounds access (of msgs).<br /> <br /> Initialize msg_write_idx before calling i2c_dw_xfer_init().

Impact