In the Linux kernel, the following vulnerability has been resolved:
soundwire: qcom: fix storing port config out-of-bounds
The 'qcom_swrm_ctrl->pconfig' has size of QCOM_SDW_MAX_PORTS (14), however we index it starting from 1, not 0, to match real port numbers. This can lead to writing port config past 'pconfig' bounds and overwriting next member of 'qcom_swrm_ctrl' struct. Reported also by smatch:
drivers/soundwire/qcom.c:1269 qcom_swrm_get_port_config() error: buffer overflow 'ctrl->pconfig' 14 <= 14
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 3, 2025 | Oct 3, 2025 |
| Redhat_linux | — | No solution existsUpgrade kernelUpgrade kernel-rt | Nov 14, 2025 | Oct 1, 2025 |
| Ubuntu | — | Upgrade linux-azureUpgrade linux-kvmUpgrade linux-aws-5.15Upgrade linux-nvidia-tegraUpgrade linux-ibmUpgrade linux-gkeUpgrade linux-lowlatencyUpgrade linux-nvidiaUpgrade linux-azure-5.15Upgrade linux-oracle-5.15Upgrade linux-oracleUpgrade linux-xilinx-zynqmpUpgrade linux-gkeopUpgrade linuxUpgrade linux-hwe-5.15Upgrade linux-raspiUpgrade linux-ibm-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-awsUpgrade linux-realtimeUpgrade linux-nvidia-tegra-5.15Upgrade linux-intel-iotgUpgrade linux-gcp-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-gcpUpgrade linux-bluefieldUpgrade linux-riscv-5.15Upgrade linux-nvidia-tegra-igxUpgrade linux-intel-iotg-5.15 | Oct 10, 2025 | Oct 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub