CVE-2025-23157
In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of bound access There
CVSS
7.8
High
EPSS
0.2%
p11
KEV
—
Exploit Today
3
0-100
Published: May 1, 2025 · Last modified: Jul 30, 2026 · CWE-125
0.2%EPSS · 30 days0.2%
2026-07-172026-08-13
In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of bound access There is a possibility that init_codecs is invoked multiple times during manipulated payload from video firmware. In such case, if codecs_count can get incremented to value more than MAX_CODEC_NUM, there can be OOB access. Reset the count so that it always starts from beginning.
- git.kernel.orghttps://git.kernel.org/stable/c/172bf5a9ef70a399bb227809db78442dc01d9e48
- git.kernel.orghttps://git.kernel.org/stable/c/1ad6aa1464b8a5ce5c194458315021e8d216108e
- git.kernel.orghttps://git.kernel.org/stable/c/26bbedd06d85770581fda5d78e78539bb088fad1
- git.kernel.orghttps://git.kernel.org/stable/c/2b8b9ea4e26a501eb220ea189e42b4527e65bdfa
- git.kernel.orghttps://git.kernel.org/stable/c/53e376178ceacca3ef1795038b22fc9ef45ff1d3
- git.kernel.orghttps://git.kernel.org/stable/c/b2541e29d82da8a0df728aadec3e0a8db55d517b
- git.kernel.orghttps://git.kernel.org/stable/c/cb5be9039f91979f8a2fac29f529f746d7848f3e
- git.kernel.orghttps://git.kernel.org/stable/c/d4d88ece4ba91df5b02f1d3f599650f9e9fc0f45
- git.kernel.orghttps://git.kernel.org/stable/c/e5133a0b25463674903fdc0528e0a29b7267130e
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-492825.1 MED—
———Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instruction-name tables, but the M68K and RISCV backends have missing or incomplete bounds checks. On a Capstone handle opened for M68K or RISCV, a caller-controlled invalid instruction ID can trigger an out-of-bounds read and crash the process. The demonstrated impact is availability loss in applications or bindings that expose instruction-name lookup to untrusted IDs. No code execution or data disclosure was demonstrated. Version 6.0.0-Alpha9 patches the issue.17hCVE-2026-180205.3 MED—
———IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.16hCVE-2026-176495.3 MED—
———IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.16hCVE-2026-172265.4 MED—
———IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.16hCVE-2026-172125.3 MED—
———IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.16hCVE-2026-168785.4 MED—
———IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.18h