In the Linux kernel, the following vulnerability has been resolved:
Input: ims-pcu - check record size in ims_pcu_flash_firmware()
The "len" variable comes from the firmware and we generally do
trust firmware, but it's always better to double check. If the "len"
is too large it could result in memory corruption when we do
"memcpy(fragment->data, rec->data, len);"
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Sat, 26 Jul 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linux
Linux linux Kernel |
|
Vendors & Products |
Linux
Linux linux Kernel |
Fri, 25 Jul 2025 14:30:00 +0000

Status: PUBLISHED
Assigner: Linux
Published: 2025-07-25T14:16:48.019Z
Updated: 2025-07-28T04:21:53.615Z
Reserved: 2025-04-16T04:51:24.015Z
Link: CVE-2025-38428

No data.

Status : Awaiting Analysis
Published: 2025-07-25T15:15:27.737
Modified: 2025-07-25T15:29:19.837
Link: CVE-2025-38428
