cbcvebase.
CVE-2025-71136
published 2026-01-14

CVE-2025-71136: In the Linux kernel, the following vulnerability has been resolved: media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status() It's…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved: media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status() It's possible for cp_read() and hdmi_read() to return -EIO. Those values are further used as indexes for accessing arrays. Fix that by checking return values where it's needed. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= a89bcd4c6c2023615a89001b5a11b0bb77eb9491 < f81ee181cb036d046340c213091b69d9a8701a76f81ee181cb036d046340c213091b69d9a8701a76
linuxlinux>= a89bcd4c6c2023615a89001b5a11b0bb77eb9491 < f913b9a2ccd6114b206b9e91dae5e3dc13a415a0f913b9a2ccd6114b206b9e91dae5e3dc13a415a0
linuxlinux>= a89bcd4c6c2023615a89001b5a11b0bb77eb9491 < d6a22a4a96e4dfe6897cb3532d2b3016d87706f0d6a22a4a96e4dfe6897cb3532d2b3016d87706f0
linuxlinux>= a89bcd4c6c2023615a89001b5a11b0bb77eb9491 < a73881ae085db5702d8b13e2fc9f78d51c723d3fa73881ae085db5702d8b13e2fc9f78d51c723d3f
linuxlinux>= a89bcd4c6c2023615a89001b5a11b0bb77eb9491 < 60dde0960e3ead8a9569f6c494d90d0232ac098360dde0960e3ead8a9569f6c494d90d0232ac0983
linuxlinux>= a89bcd4c6c2023615a89001b5a11b0bb77eb9491 < b693d48a6ed0cd09171103ad418e4a693203d6e4b693d48a6ed0cd09171103ad418e4a693203d6e4
linuxlinux>= a89bcd4c6c2023615a89001b5a11b0bb77eb9491 < 8163419e3e05d71dcfa8fb49c8fdf8d76908fe518163419e3e05d71dcfa8fb49c8fdf8d76908fe51
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 3.12.0 < 5.10.2485.10.248

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.