In the Linux kernel, the following vulnerability has been resolved:
soc: qcom: qmi_encdec: Restrict string length in decode
The QMI TLV value for strings in a lot of qmi element info structures account for null terminated strings with MAX_LEN + 1. If a string is actually MAX_LEN + 1 length, this will cause an out of bounds access when the NULL character is appended in decoding.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 24, 2025 | Oct 24, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 22, 2025 |
| Ubuntu | — | Upgrade linux-bluefieldUpgrade linux-ibmUpgrade linux-xilinx-zynqmpUpgrade linux-azure-5.15Upgrade linux-realtimeUpgrade linux-oracleUpgrade linux-aws-fipsUpgrade linux-intel-iotg-5.15Upgrade linux-azure-5.4Upgrade linux-intel-iotgUpgrade linux-kvmUpgrade linux-raspi-5.4Upgrade linux-aws-5.4Upgrade linux-fipsUpgrade linux-azureUpgrade linux-aws-5.15Upgrade linux-raspiUpgrade linux-iotUpgrade linux-lowlatency-hwe-5.15Upgrade linux-gcp-5.15Upgrade linux-riscv-5.15Upgrade linux-nvidiaUpgrade linux-hwe-5.15Upgrade linux-oracle-5.15Upgrade linux-gkeopUpgrade linux-ibm-5.4Upgrade linux-awsUpgrade linux-nvidia-tegra-igxUpgrade linux-nvidia-tegraUpgrade linux-lowlatencyUpgrade linux-ibm-5.15Upgrade linux-hwe-5.4Upgrade linux-gcpUpgrade linux-azure-fipsUpgrade linux-nvidia-tegra-5.15Upgrade linuxUpgrade linux-intel-iot-realtimeUpgrade linux-gcp-5.4Upgrade linux-gkeUpgrade linux-oracle-5.4Upgrade linux-gcp-fips | Oct 28, 2025 | Oct 24, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Oct 22, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub