In the Linux kernel, the following vulnerability has been resolved:
soc: qcom: qmi_encdec: Restrict string length in decode
The QMI TLV value for strings in a lot of qmi element info structures account for null terminated strings with MAX_LEN + 1. If a string is actually MAX_LEN + 1 length, this will cause an out of bounds access when the NULL character is appended in decoding.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 24, 2025 | Oct 24, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 22, 2025 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-hwe-5.4Upgrade linux-gkeUpgrade linux-oracle-5.4Upgrade linux-ibm-5.15Upgrade linux-gcpUpgrade linux-gcp-5.4Upgrade linux-ibm-5.4Upgrade linux-azure-fipsUpgrade linux-nvidia-tegra-igxUpgrade linux-nvidia-tegraUpgrade linux-intel-iot-realtimeUpgrade linux-gkeopUpgrade linux-gcp-fipsUpgrade linux-nvidia-tegra-5.15Upgrade linux-lowlatencyUpgrade linuxUpgrade linux-raspiUpgrade linux-aws-fipsUpgrade linux-realtimeUpgrade linux-aws-5.4Upgrade linux-aws-5.15Upgrade linux-gcp-5.15Upgrade linux-ibmUpgrade linux-kvmUpgrade linux-nvidiaUpgrade linux-intel-iotgUpgrade linux-azure-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-bluefieldUpgrade linux-azure-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-xilinx-zynqmpUpgrade linux-hwe-5.15Upgrade linux-raspi-5.4Upgrade linux-azureUpgrade linux-oracleUpgrade linux-oracle-5.15Upgrade linux-fipsUpgrade linux-riscv-5.15Upgrade linux-iot | Oct 28, 2025 | Oct 24, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Oct 22, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub