CVE-2025-37979: ASoC: qcom: Fix sc7280 lpass potential buffer overflow
Published May 20, 2025
·Updated
ASoC: qcom: Fix sc7280 lpass potential buffer overflow
Affected Software
10 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=5.18<6.1.136
Linux Linux kernel>=6.2<6.6.88
Linux Linux kernel>=6.7<6.12.25
Linux Linux kernel>=6.13<6.14.4
Linux Linux kernel=6.15-rc1
Linux Linux kernel=6.15-rc2
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.85.1-4
Microsoft azl3 kernel 6.6.92.2-1
Event History
May 20, 2025
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 11, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-37979?
CVE-2025-37979 is categorized as a potential buffer overflow issue in the Linux kernel, which could lead to security vulnerabilities.
2
How do I fix CVE-2025-37979?
To mitigate CVE-2025-37979, ensure that your Linux kernel is updated to the latest stable version that includes the fix for this vulnerability.
3
What are the potential impacts of CVE-2025-37979?
The impacts of CVE-2025-37979 may include system instability or exploitation leading to unauthorized access due to buffer overflow.
4
Which systems are affected by CVE-2025-37979?
CVE-2025-37979 affects systems utilizing the Linux kernel that implement the sc7280 audio driver.
5
Is CVE-2025-37979 actively being exploited?
At this time, there have been no confirmed reports of active exploitation related to CVE-2025-37979.