In the Linux kernel, the following vulnerability has been resolved:
regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
drvdata::gpiods is supposed to hold an array of 'gpio_desc' pointers. But
the memory is allocated for only one pointer. This will lead to
out-of-bounds access later in the code if 'config::ngpios' is > 1. So
fix the code to allocate enough memory to hold 'config::ngpios' of GPIO
descriptors.
While at it, also move the check for memory allocation failure to be below
the allocation to make it more readable.
CVSS
No CVSS.
References
Configurations
No configuration.
History
25 Jul 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-25 13:15
Updated : 2025-07-25 15:29
NVD link : CVE-2025-38395
Mitre link : CVE-2025-38395
CVE.ORG link : CVE-2025-38395
JSON object : View
Products Affected
No product.
CWE
No CWE.