In the Linux kernel, the following vulnerability has been resolved:
media: av7110: prevent underflow in write_ts_to_decoder()
The buf[4] value comes from the user via ts_play(). It is a value in the u8 range. The final length we pass to av7110_ipack_instant_repack() is "len - (buf[4] + 1) - 4" so add a check to ensure that the length is not negative. It's not clear that passing a negative len value does anything bad necessarily, but it's not best practice.
With the new bounds checking the "if (!len)" condition is no longer possible or required so remove that.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Ubuntu | — | Upgrade linux-ibmUpgrade linuxUpgrade linux-riscv-5.15Upgrade linux-gcp-5.4Upgrade linux-fipsUpgrade linux-intel-iot-realtimeUpgrade linux-aws-fipsUpgrade linux-iotUpgrade linux-nvidia-tegra-igxUpgrade linux-lowlatencyUpgrade linux-nvidiaUpgrade linux-hwe-5.4Upgrade linux-gcpUpgrade linux-azure-5.4Upgrade linux-ibm-5.4Upgrade linux-intel-iotgUpgrade linux-oracle-5.15Upgrade linux-gcp-fipsUpgrade linux-kvmUpgrade linux-oracleUpgrade linux-intel-iotg-5.15Upgrade linux-azure-fipsUpgrade linux-azure-5.15Upgrade linux-xilinx-zynqmpUpgrade linux-gkeopUpgrade linux-oracle-5.4Upgrade linux-aws-5.15Upgrade linux-azureUpgrade linux-hwe-5.15Upgrade linux-nvidia-tegraUpgrade linux-nvidia-tegra-5.15Upgrade linux-realtimeUpgrade linux-ibm-5.15Upgrade linux-gcp-5.15Upgrade linux-bluefieldUpgrade linux-raspi-5.4Upgrade linux-raspiUpgrade linux-gkeUpgrade linux-lowlatency-hwe-5.15Upgrade linux-aws-5.4Upgrade linux-aws | Jan 6, 2026 | Jan 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Dec 30, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub