CVE-2025-38680

Updated: 2026-02-08 04:04:58.653342

Description:

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen > 2), buf the function accesses buffer[3], requiring at least 4 bytes. This can lead to an out-of-bounds read if the buffer has exactly 3 bytes. Fix it by checking that the buffer has at least 4 bytes in uvc_parse_format().


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH In Progress 2026-02-05 12:23:39
CentOS 6 ELS kernel 2.6.32 7.1 HIGH In Testing 2026-02-04 11:02:06
CentOS 7 ELS kernel 3.10.0 7.1 HIGH In Testing 2026-02-04 11:02:04
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2026:1771078945 2026-02-14 20:11:27
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2026:1771077729 2026-02-14 20:11:28
CentOS Stream 8 ELS kernel 4.18.0 7.1 HIGH In Progress 2026-02-05 12:23:38
CloudLinux 7 ELS kernel 3.10.0 7.1 HIGH Needs Triage 2026-02-04 10:07:53
Oracle Linux 6 ELS kernel 2.6.32 7.1 HIGH Needs Triage 2026-02-04 10:07:46
Oracle Linux 7 ELS kernel 3.10.0 7.1 HIGH Needs Triage 2026-02-04 10:07:50
Oracle Linux 7 ELS kernel-uek 5.4.17 7.1 HIGH Already Fixed 2026-02-06 09:10:48
Total: 16