-

CVE-2025-68819

In the Linux kernel, the following vulnerability has been resolved:

media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()

rlen value is a user-controlled value, but dtv5100_i2c_msg() does not
check the size of the rlen value. Therefore, if it is set to a value
larger than sizeof(st->data), an out-of-bounds vuln occurs for st->data.

Therefore, we need to add proper range checking to prevent this vuln.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < c2c293ea7b61f12cdaad1e99a5b4efc58c88960a
Version 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817
Status affected
Version < c2305b4c5fc15e20ac06c35738e0578eb4323750
Version 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817
Status affected
Version < 61f214a878e96e2a8750bf96a98f78c658dba60c
Version 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817
Status affected
Version < 4a54d8fcb093761e4c56eb211cf4e39bf8401fa1
Version 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817
Status affected
Version < fe3e129ab49806aaaa3f22067ebc75c2dfbe4658
Version 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817
Status affected
Version < ac92151ff2494130d9fc686055d6bbb9743a673e
Version 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817
Status affected
Version < b91e6aafe8d356086cc621bc03e35ba2299e4788
Version 60688d5e6e6e2ae62f29762d1e3b2aec2dbd3817
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.28
Status affected
Version < 2.6.28
Version 0
Status unaffected
Version <= 5.10.*
Version 5.10.248
Status unaffected
Version <= 5.15.*
Version 5.15.198
Status unaffected
Version <= 6.1.*
Version 6.1.160
Status unaffected
Version <= 6.6.*
Version 6.6.120
Status unaffected
Version <= 6.12.*
Version 6.12.64
Status unaffected
Version <= 6.18.*
Version 6.18.3
Status unaffected
Version <= *
Version 6.19-rc1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.