Wind River Support Network

HomeDefectsLIN1023-12804
Fixed

LIN1023-12804 : Security Advisory - linux - CVE-2025-23157

Created: May 6, 2025    Updated: May 25, 2025
Resolved Date: May 25, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

media: venus: hfi_parser: add check to avoid out of bound access

There is a possibility that init_codecs is invoked multiple times during
manipulated payload from video firmware. In such case, if codecs_count
can get incremented to value more than MAX_CODEC_NUM, there can be OOB
access. Reset the count so that it always starts from beginning.

CREATE(Triage):(User=admin) CVE-2025-23157 (https://nvd.nist.gov/vuln/detail/CVE-2025-23157)

CVEs


Live chat
Online