In the Linux kernel, the following vulnerability has been resolved:
soundwire: qcom: fix storing port config out-of-bounds
The 'qcom_swrm_ctrl->pconfig' has size of QCOM_SDW_MAX_PORTS (14), however we index it starting from 1, not 0, to match real port numbers. This can lead to writing port config past 'pconfig' bounds and overwriting next member of 'qcom_swrm_ctrl' struct. Reported also by smatch:
drivers/soundwire/qcom.c:1269 qcom_swrm_get_port_config() error: buffer overflow 'ctrl->pconfig' 14 <= 14
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 3, 2025 | Oct 3, 2025 |
| Redhat_linux | — | Upgrade kernel-rtNo solution existsUpgrade kernel | Nov 14, 2025 | Oct 1, 2025 |
| Ubuntu | — | Upgrade linux-bluefieldUpgrade linux-gcp-5.15Upgrade linux-awsUpgrade linux-nvidia-tegra-5.15Upgrade linux-intel-iotgUpgrade linux-lowlatency-hwe-5.15Upgrade linux-riscv-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-nvidia-tegra-igxUpgrade linux-realtimeUpgrade linux-gcpUpgrade linux-intel-iot-realtimeUpgrade linux-azureUpgrade linux-gkeopUpgrade linux-aws-5.15Upgrade linuxUpgrade linux-lowlatencyUpgrade linux-azure-5.15Upgrade linux-nvidiaUpgrade linux-hwe-5.15Upgrade linux-raspiUpgrade linux-ibm-5.15Upgrade linux-xilinx-zynqmpUpgrade linux-oracleUpgrade linux-gkeUpgrade linux-oracle-5.15Upgrade linux-ibmUpgrade linux-kvmUpgrade linux-nvidia-tegra | Oct 10, 2025 | Oct 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub