CVE-2025-38330
HIGHLinux Kernel 6.14-6.15.3 - Out-of-bounds Read in cs_dsp_ctl_cache_init_multiple_offsets
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUnit test (ctl cache) KASAN reported out of bounds access - cs_dsp_ctl_cache_init_multiple_offsets(). The code uses mock_coeff_template.length_bytes (4 bytes) for register value allocations. But later, this length is set to 8 bytes which causes test code failures. As fix, just remove the lenght override, keeping the original value 4 for all operations.
References (2)
Core 2
Scores
CVSS v3
7.1
EPSS
0.0014
EPSS Percentile
4.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Details
CWE
CWE-125
Status
published
Products (8)
linux/Kernel
6.14.0 - 6.15.4linux
Linux/Linux
< 6.14
Linux/Linux
6.14
Linux/Linux
6.15.4 - 6.15.*
Linux/Linux
6.16
Linux/Linux
9b33a4fc500cedc1adc9c0ee01e30ffd50e5887a - e3dafc64b90546eb769f33333afabd9e3e915757
Linux/Linux
9b33a4fc500cedc1adc9c0ee01e30ffd50e5887a - f4ba2ea57da51d616b689c4b8826c517ff5a8523
linux/linux_kernel
6.14 - 6.15.4
Published
Jul 10, 2025
Tracked Since
Feb 18, 2026