CVE-2025-39710
In the Linux kernel, the following vulnerability has been resolved: media: venus: Add a check for packet size after reading from shared mem
CVSS
7.8
High
EPSS
0.2%
p5
KEV
—
Exploit Today
2
0-100
Published: Sep 5, 2025 · Last modified: Jul 30, 2026 · CWE-125
0.2%EPSS · 30 days0.2%
2026-07-032026-07-30
In the Linux kernel, the following vulnerability has been resolved: media: venus: Add a check for packet size after reading from shared memory Add a check to ensure that the packet size does not exceed the number of available words after reading the packet header from shared memory. This ensures that the size provided by the firmware is safe to process and prevent potential out-of-bounds memory access.
- git.kernel.orghttps://git.kernel.org/stable/c/0520c89f6280d2b60ab537d5743601185ee7d8ab
- git.kernel.orghttps://git.kernel.org/stable/c/2d8cea8310a245730816a1fd0c9fa4a5a3bdc68c
- git.kernel.orghttps://git.kernel.org/stable/c/49befc830daa743e051a65468c05c2ff9e8580e6
- git.kernel.orghttps://git.kernel.org/stable/c/7638bae4539dcebc3f68fda74ac35d73618ec440
- git.kernel.orghttps://git.kernel.org/stable/c/ba567c2e52fbcf0e20502746bdaa79e911c2e8cf
- git.kernel.orghttps://git.kernel.org/stable/c/ef09b96665f16f3f0bac4e111160e6f24f1f8791
- git.kernel.orghttps://git.kernel.org/stable/c/f0cbd9386f974d310a0d20a02e4a1323e95ea654
- git.kernel.orghttps://git.kernel.org/stable/c/f5b7a943055a4a106d40a03bacd940e28cc1955f
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/html/ssa-032379.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-62959——
———Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single ordinary HTTP GET request and receive a 301 response whose Location header contains up to ~870 bytes of adjacent process heap memory. The leaked region is a recycled network receive buffer that is reused without being zeroed, so on a busy server it can contain data from other clients' requests (TURN credentials, OAuth tokens, relayed payloads). Root cause is a signed→unsigned conversion. This issue is fixed in version 4.15.0.9hCVE-2026-667206.5 MED—
——0The GOOSE subscriber component improperly validates the UTC timestamp
field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2
multicast messages. A specially crafted GOOSE frame containing an
undersized timestamp field can trigger a heap out-of-bounds read during
message processing, causing the process to crash and resulting in a
denial-of-service condition.13hCVE-2026-663696.5 MED—
——0The GOOSE parser contains an off-by-one boundary-handling flaw that can
be triggered by a single unauthenticated Layer-2 multicast frame on the
process bus. When specific GOOSE message fields are processed, the
parser advances its internal buffer position incorrectly, resulting in a
heap out-of-bounds read. On affected platforms, this condition reliably
terminates the subscriber process and causes a denial-of-service.9hCVE-2026-663646.5 MED—
——0The GOOSE payload parser contains a boundary handling flaw that can be
triggered by a single unauthenticated Layer 2 multicast frame on the
process bus. When processing specific payload fields, an attacker
controlled inner element length may exceed its enclosing length, causing
the parser to over read by one byte. This out-of-bounds read reliably
terminates the subscriber process, resulting in a denial-of-service
condition.13hCVE-2026-663607.5 HIG—
——0The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled field with a zero length value to trigger a bounded heap over
read. This condition occurs before MMS session establishment, a crafted
TCP/102 connection attempt can trigger the issue. The resulting over
read causes the process to terminate, leading to a denial of service
condition.13hCVE-2026-663496.5 MED—
——0The MMS server connection handler contains a flaw in its processing of
BER-encoded request data. When an MMS confirmed request PDU containing
an extended BER tag is received over an established session, the decoder
may advance its internal buffer incorrectly due to a missing bounds
check. This results in a one byte heap out-of-bounds read and causes the
MMS service process to terminate, leading to a denial-of-service
condition.13h