AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-23157

HIGH · CVSS 7.8 EPSS 0.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-05-01 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Linux.

CVE
CVE-2025-23157
Severity
HIGH
CVSS
7.8
EPSS
0.21%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of bound access There is a possibility that init_codecs is invoked multiple times during manipulated payload from video firmware. In such case, if codecs_count can get incremented to value more than MAX_CODEC_NUM, there can be OOB access. Reset the count so that it always starts from beginning.

Related CVEs

Other vulnerabilities affecting the same vendor(s)