CVE Vulnerabilities

CVE-2025-39680

Published: Sep 05, 2025 | Modified: Sep 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu

In the Linux kernel, the following vulnerability has been resolved:

i2c: rtl9300: Fix out-of-bounds bug in rtl9300_i2c_smbus_xfer

The data->block[0] variable comes from user. Without proper check, the variable may be very large to cause an out-of-bounds bug.

Fix this bug by checking the value of data->block[0] first.

  1. commit 39244cc75482 (i2c: ismt: Fix an out-of-bounds bug in ismt_access())
  2. commit 92fbb6d1296f (i2c: xgene-slimpro: Fix out-of-bounds bug in xgene_slimpro_i2c_xfer())

References