We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-38068

crypto: lzo - Fix compression buffer overrun



Description

In the Linux kernel, the following vulnerability has been resolved: crypto: lzo - Fix compression buffer overrun Unlike the decompression code, the compression code in LZO never checked for output overruns. It instead assumes that the caller always provides enough buffer space, disregarding the buffer length provided by the caller. Add a safe compression interface that checks for the end of buffer before each write. Use the safe interface in crypto/lzo.

Reserved 2025-04-16 | Published 2025-06-18 | Updated 2025-06-18 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 4b173bb2c4665c23f8fcf5241c7b06dfa6b5b111
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before a98bd864e16f91c70b2469adf013d713d04d1d13
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 0acdc4d6e679ba31d01e3e7e2e4124b76d6d8e2a
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 7caad075acb634a74911830d6386c50ea12566cd
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 167373d77c70c2b558aae3e327b115249bb2652c
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before cc47f07234f72cbd8e2c973cdbf2a6730660a463
affected

Default status
affected

5.15.185
unaffected

6.1.141
unaffected

6.6.93
unaffected

6.12.31
unaffected

6.14.9
unaffected

6.15
unaffected

References

git.kernel.org/...c/4b173bb2c4665c23f8fcf5241c7b06dfa6b5b111

git.kernel.org/...c/a98bd864e16f91c70b2469adf013d713d04d1d13

git.kernel.org/...c/0acdc4d6e679ba31d01e3e7e2e4124b76d6d8e2a

git.kernel.org/...c/7caad075acb634a74911830d6386c50ea12566cd

git.kernel.org/...c/167373d77c70c2b558aae3e327b115249bb2652c

git.kernel.org/...c/cc47f07234f72cbd8e2c973cdbf2a6730660a463

cve.org (CVE-2025-38068)

nvd.nist.gov (CVE-2025-38068)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-38068

Support options

Helpdesk Chat, Email, Knowledgebase