cbcvebase.
CVE-2025-23159
published 2025-05-01

CVE-2025-23159: In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than actual sfr data buffer. Cap the size to allocated size for such cases.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < 4dd109038d513b92d4d33524ffc89ba32e02ba484dd109038d513b92d4d33524ffc89ba32e02ba48
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < 8879397c0da5e5ec1515262995e82cdfd61b282a8879397c0da5e5ec1515262995e82cdfd61b282a
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < 1b8fb257234e7d2d4b3f48af07c5aa5e11c716341b8fb257234e7d2d4b3f48af07c5aa5e11c71634
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < 4e95233af57715d81830fe82b408c633edff59f44e95233af57715d81830fe82b408c633edff59f4
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < 5af611c70fb889d46d2f654b8996746e595567505af611c70fb889d46d2f654b8996746e59556750
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < 530f623f56a6680792499a8404083e17f8ec51f4530f623f56a6680792499a8404083e17f8ec51f4
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < a062d8de0be5525ec8c52f070acf7607ec8cbfe4a062d8de0be5525ec8c52f070acf7607ec8cbfe4
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < d78a8388a27b265fcb2b8d064f088168ac9356b0d78a8388a27b265fcb2b8d064f088168ac9356b0
linuxlinux>= d96d3f30c0f2f564f6922bf4ccdf4464992e31fb < f4b211714bcc70effa60c34d9fa613d182e3ef1ef4b211714bcc70effa60c34d9fa613d182e3ef1e
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.13 < 5.4.2935.4.293
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.13.126.13.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.