CVE-2025-38585

staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()

References

Notes

 carnil> Introduced in 38d4f74bc148 ("media: atomisp_gmin_platform: stop abusing efivar
 carnil> API"). Vulnerable versions: 6.0.

Bugs

Status

Branch Status
upstream released (6.17-rc1) [ee4cf798202d285dcbe85e4467a094c44f5ed8e6]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.16-upstream-stable released (6.16.1) [1a7a2f59fb2eb0718a0cff1e5822500cefe50ed9]
6.15-upstream-stable released (6.15.10) [e6d3453a002e89537e6136f6c774659b297a549b]
6.12-upstream-stable released (6.12.42) [3d672fe065aa00f4d66f42e3c9720f69a3ed43e7]
6.6-upstream-stable needed
6.1-upstream-stable needed
5.10-upstream-stable N/A "Vulnerable code not present"
sid released (6.16.3-1)
6.12-trixie-security released (6.12.43-1)
6.1-bookworm-security needed
5.10-bullseye-security N/A "Vulnerable code not present"