CVE-2025-38425

medium

Description

In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: check msg length in SMBUS block read For SMBUS block read, do not continue to read if the message length passed from the device is '0' or greater than the maximum allowed bytes.

References

https://git.kernel.org/stable/c/c39d1a9ae4ad66afcecab124d7789722bfe909fa

https://git.kernel.org/stable/c/be5f6a65509cd5675362f15eb0440fb28b0f9d64

https://git.kernel.org/stable/c/a6e04f05ce0b070ab39d5775580e65c7d943da0b

https://git.kernel.org/stable/c/75a864f21ceeb8c1e8ce1b7589174fec2c3a039e

https://git.kernel.org/stable/c/3f03f77ce688d02da284174e1884b6065d6159bd

Details

Source: Mitre, NVD

Published: 2025-07-25

Updated: 2025-07-25

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00018