SB2025121535 - Out-of-bounds read in Linux kernel usb storage driver
Published: December 15, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2025-40345)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the sddr55_write_data() function in drivers/usb/storage/sddr55.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04a8a6393f3f2f471e05eacca33282dd30b01432
- https://git.kernel.org/stable/c/26e9b5da3231da7dc357b363883b5b7b51a64092
- https://git.kernel.org/stable/c/5ebe8d479aaf4f41ac35e6955332304193c646f6
- https://git.kernel.org/stable/c/a20f1dd19d21dcb70140ea5a71b1f8cbe0c7e68f
- https://git.kernel.org/stable/c/aa64e0e17e3a5991a25e6a46007770c629039869
- https://git.kernel.org/stable/c/b59d4fda7e7d0aff1043a7f742487cb829f5aac1
- https://git.kernel.org/stable/c/d00a6c04a502cd52425dbf35588732c652b16490