media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()

Summary

CVECVE-2025-38680
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2025-09-04 16:15:35 UTC
Updated2026-05-12 13:16:54 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen > 2), buf the function accesses buffer[3], requiring at least 4 bytes. This can lead to an out-of-bounds read if the buffer has exactly 3 bytes. Fix it by checking that the buffer has at least 4 bytes in uvc_parse_format().

Risk And Classification

Primary CVSS: v3.1 7.1 HIGH from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Problem Types: CWE-125

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c 9ad554217c9b945031c73df4e8176a475e2dea57 git Not specified
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c 1e269581b3aa5962fdc52757ab40da286168c087 git Not specified
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c 8343f3fe0b755925f83d60b05e92bf4396879758 git Not specified
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c ffdd82182953df643aa63d999b6f1653d0c93778 git Not specified
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c a97e062e4ff3dab84a2f1eb811e9eddc6699e2a9 git Not specified
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c cac702a439050df65272c49184aef7975fe3eff2 git Not specified
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c 424980d33b3f816485513e538610168b03fab9f1 git Not specified
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c 6d4a7c0b296162354b6fc759a1475b9d57ddfaa6 git Not specified
CNA Linux Linux affected c0efd232929c2cd87238de2cccdaf4e845be5b0c 782b6a718651eda3478b1824b37a8b3185d2740c git Not specified
CNA Linux Linux affected 2.6.26 Not specified
CNA Linux Linux unaffected 2.6.26 semver Not specified
CNA Linux Linux unaffected 5.4.297 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.241 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.190 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.149 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.103 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.43 6.12.* semver Not specified
CNA Linux Linux unaffected 6.15.11 6.15.* semver Not specified
CNA Linux Linux unaffected 6.16.2 6.16.* semver Not specified
CNA Linux Linux unaffected 6.17 * original_commit_for_fix Not specified
ADP Siemens SIMATIC CN 4100 affected V5.0 custom Not specified

References

ReferenceSourceLinkTags
lists.debian.org/debian-lts-announce/2025/10/msg00008.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Third Party Advisory
git.kernel.org/stable/c/8343f3fe0b755925f83d60b05e92bf4396879758 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/ffdd82182953df643aa63d999b6f1653d0c93778 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/cac702a439050df65272c49184aef7975fe3eff2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/782b6a718651eda3478b1824b37a8b3185d2740c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/a97e062e4ff3dab84a2f1eb811e9eddc6699e2a9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/1e269581b3aa5962fdc52757ab40da286168c087 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
cert-portal.siemens.com/productcert/html/ssa-032379.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e cert-portal.siemens.com
git.kernel.org/stable/c/424980d33b3f816485513e538610168b03fab9f1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/9ad554217c9b945031c73df4e8176a475e2dea57 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/6d4a7c0b296162354b6fc759a1475b9d57ddfaa6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2025/10/msg00007.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report