SB20250502273 - Buffer overflow in Linux kernel gt uc driver
Published: May 2, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2025-37754)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the intel_uc_init_late() function in drivers/gpu/drm/i915/gt/uc/intel_uc.c, within the intel_huc_init_early() and intel_huc_fini() functions in drivers/gpu/drm/i915/gt/uc/intel_huc.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4bd4bf79bcfe101f0385ab81dbabb6e3f7d96c00
- https://git.kernel.org/stable/c/9f5ef4a5eaa61a7a4ed31231da45deb85065397a
- https://git.kernel.org/stable/c/c5a906806162aea62dbe5d327760ce3b7117ca17
- https://git.kernel.org/stable/c/e3ea2eae70692a455e256787e4f54153fb739b90
- https://git.kernel.org/stable/c/f104ef4db9f8f3923cc06ed1fafb3da38df6006d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.3