media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
Published Sep 4, 2025
7.1
HIGHCVSS 3.1
EPSS 0.18%
Description
The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen > 2), buf the function accesses buffer[3], requiring at least 4 bytes.
This can lead to an out-of-bounds read if the buffer has exactly 3 bytes.
Fix it by checking that the buffer has at least 4 bytes in uvc_parse_format().
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 2.6.26
Unaffected
- ≥ 0, < 2.6.26
- ≥ 5.10.241, ≤ 5.10.*
- ≥ 5.15.190, ≤ 5.15.*
- ≥ 5.4.297, ≤ 5.4.*
- ≥ 6.1.149, ≤ 6.1.*
- ≥ 6.12.43, ≤ 6.12.*
- ≥ 6.15.11, ≤ 6.15.*
- ≥ 6.16.2, ≤ 6.16.*
- 6.17
- ≥ 6.6.103, ≤ 6.6.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
Configuration 1
- ≥ 2.6.27 · < 5.4.297
- ≥ 5.5 · < 5.10.241
- ≥ 5.11 · < 5.15.190
- ≥ 5.16 · < 6.1.149
- ≥ 6.2 · < 6.6.103
- ≥ 6.7 · < 6.12.43
- ≥ 6.13 · < 6.15.11
- ≥ 6.16 · < 6.16.2
- 2.6.26
- 2.6.26
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A flaw was found in the Linux kernel UVC video driver where uvc_parse_format() could perform a one-byte out-of-bounds read when parsing a format descriptor if the buffer length was exactly three bytes. This can only cause an invalid read of uninitialized memory, leading at most to a local denial of service.
Red Hat mitigation
To mitigate this issue, prevent module uvcvideo from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
References (18)
- https://access.redhat.com/security/cve/CVE-2025-38680 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2393159 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26789 Advisory
- https://git.kernel.org/stable/c/1e269581b3aa5962fdc52757ab40da286168c087 Patch
- https://git.kernel.org/stable/c/424980d33b3f816485513e538610168b03fab9f1 Patch
- https://git.kernel.org/stable/c/6d4a7c0b296162354b6fc759a1475b9d57ddfaa6 Patch
- https://git.kernel.org/stable/c/782b6a718651eda3478b1824b37a8b3185d2740c Patch
- https://git.kernel.org/stable/c/8343f3fe0b755925f83d60b05e92bf4396879758 Patch
- https://git.kernel.org/stable/c/9ad554217c9b945031c73df4e8176a475e2dea57 Patch
- https://git.kernel.org/stable/c/a97e062e4ff3dab84a2f1eb811e9eddc6699e2a9 Patch
- https://git.kernel.org/stable/c/cac702a439050df65272c49184aef7975fe3eff2 Patch
- https://git.kernel.org/stable/c/ffdd82182953df643aa63d999b6f1653d0c93778 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Third Party Advisory
- https://lore.kernel.org/linux-cve-announce/2025090445-CVE-2025-38680-cce6@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-38680
- https://www.cve.org/CVERecord?id=CVE-2025-38680
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data