CVE-2025-38401
In the Linux kernel, the following vulnerability has been resolved: mtk-sd: Prevent memory corruption from DMA map failure If msdc_prepare
CVSS
7.8
High
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Published: Jul 25, 2025 · Last modified: Jul 30, 2026 · CWE-787
0.2%EPSS · 30 days0.2%
2026-07-052026-08-02
In the Linux kernel, the following vulnerability has been resolved: mtk-sd: Prevent memory corruption from DMA map failure If msdc_prepare_data() fails to map the DMA region, the request is not prepared for data receiving, but msdc_start_data() proceeds the DMA with previous setting. Since this will lead a memory corruption, we have to stop the request operation soon after the msdc_prepare_data() fails to prepare it.
- git.kernel.orghttps://git.kernel.org/stable/c/3419bc6a7b65cbbb91417bb9970208478e034c79
- git.kernel.orghttps://git.kernel.org/stable/c/48bf4f3dfcdab02b22581d8e350a2d23130b72c0
- git.kernel.orghttps://git.kernel.org/stable/c/5ac9e9e2e9cd6247d8c2d99780eae4556049e1cc
- git.kernel.orghttps://git.kernel.org/stable/c/61cdd663564674ea21ceb50aa9d3697cbe9e45f9
- git.kernel.orghttps://git.kernel.org/stable/c/63e8953f16acdcb23e2d4dd8a566d3c34df3e200
- git.kernel.orghttps://git.kernel.org/stable/c/a5f5f67b284d81776d4a3eb1f8607e4b7f91f11c
- git.kernel.orghttps://git.kernel.org/stable/c/d54771571f74a82c59830a32e76af78a8e57ac69
- git.kernel.orghttps://git.kernel.org/stable/c/f5de469990f19569627ea0dd56536ff5a13beaa3
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-20497——
——0In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.13hCVE-2026-20493——
——0In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.13hCVE-2026-20491——
——0In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.13hCVE-2026-20485——
——0In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.13hCVE-2026-20481——
——0In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.13hCVE-2026-20478——
——0In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.13h