Wind River Support Network

HomeDefectsLIN1022-15348
Fixed

LIN1022-15348 : Security Advisory - linux - CVE-2025-23159

Created: May 6, 2025    Updated: Jun 10, 2025
Resolved Date: May 28, 2025
Found In Version: 10.22.33.1
Fix Version: 10.22.33.21
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

media: venus: hfi: add a check to handle OOB in sfr region

sfr->buf_size is in shared memory and can be modified by malicious user.
OOB write is possible when the size is made higher than actual sfr data
buffer. Cap the size to allocated size for such cases.

CREATE(Triage):(User=admin) CVE-2025-23159 (https://nvd.nist.gov/vuln/detail/CVE-2025-23159)

CVEs


Live chat
Online