cbcvebase.
CVE-2025-68819
published 2026-01-13

CVE-2025-68819: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() rlen value is a…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() rlen value is a user-controlled value, but dtv5100_i2c_msg() does not check the size of the rlen value. Therefore, if it is set to a value larger than sizeof(st->data), an out-of-bounds vuln occurs for st->data. Therefore, we need to add proper range checking to prevent this vuln.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817 < c2c293ea7b61f12cdaad1e99a5b4efc58c88960ac2c293ea7b61f12cdaad1e99a5b4efc58c88960a
linuxlinux>= 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817 < c2305b4c5fc15e20ac06c35738e0578eb4323750c2305b4c5fc15e20ac06c35738e0578eb4323750
linuxlinux>= 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817 < 61f214a878e96e2a8750bf96a98f78c658dba60c61f214a878e96e2a8750bf96a98f78c658dba60c
linuxlinux>= 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817 < 4a54d8fcb093761e4c56eb211cf4e39bf8401fa14a54d8fcb093761e4c56eb211cf4e39bf8401fa1
linuxlinux>= 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817 < fe3e129ab49806aaaa3f22067ebc75c2dfbe4658fe3e129ab49806aaaa3f22067ebc75c2dfbe4658
linuxlinux>= 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817 < ac92151ff2494130d9fc686055d6bbb9743a673eac92151ff2494130d9fc686055d6bbb9743a673e
linuxlinux>= 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817 < b91e6aafe8d356086cc621bc03e35ba2299e4788b91e6aafe8d356086cc621bc03e35ba2299e4788
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 2.6.28 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.