U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CVE-2025-23159 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than actual sfr data buffer. Cap the size to allocated size for such cases.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NIST CVSS score
NIST: NVD
N/A
NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
https://git.kernel.org/stable/c/1b8fb257234e7d2d4b3f48af07c5aa5e11c71634 kernel.org
https://git.kernel.org/stable/c/4dd109038d513b92d4d33524ffc89ba32e02ba48 kernel.org
https://git.kernel.org/stable/c/4e95233af57715d81830fe82b408c633edff59f4 kernel.org
https://git.kernel.org/stable/c/530f623f56a6680792499a8404083e17f8ec51f4 kernel.org
https://git.kernel.org/stable/c/5af611c70fb889d46d2f654b8996746e59556750 kernel.org
https://git.kernel.org/stable/c/8879397c0da5e5ec1515262995e82cdfd61b282a kernel.org
https://git.kernel.org/stable/c/a062d8de0be5525ec8c52f070acf7607ec8cbfe4 kernel.org
https://git.kernel.org/stable/c/d78a8388a27b265fcb2b8d064f088168ac9356b0 kernel.org
https://git.kernel.org/stable/c/f4b211714bcc70effa60c34d9fa613d182e3ef1e kernel.org

Weakness Enumeration

CWE-ID CWE Name Source

Change History

2 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2025-23159
NVD Published Date:
05/01/2025
NVD Last Modified:
05/02/2025
Source:
kernel.org