We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-38380

i2c/designware: Fix an initialization issue



Description

In the Linux kernel, the following vulnerability has been resolved: i2c/designware: Fix an initialization issue The i2c_dw_xfer_init() function requires msgs and msg_write_idx from the dev context to be initialized. amd_i2c_dw_xfer_quirk() inits msgs and msgs_num, but not msg_write_idx. This could allow an out of bounds access (of msgs). Initialize msg_write_idx before calling i2c_dw_xfer_init().

Reserved 2025-04-16 | Published 2025-07-25 | Updated 2025-07-25 | Assigner Linux

Product status

Default status
unaffected

17631e8ca2d3421090e54b39d9a1402091019ba1 before 475f89e1f9bde45fc948589e7cde1f5d899ae412
affected

17631e8ca2d3421090e54b39d9a1402091019ba1 before 5b622e672e49e50c33fc64cd06b05ce76e1de460
affected

17631e8ca2d3421090e54b39d9a1402091019ba1 before 6358cb9c2a31e23b6b51bfcd7fe2b7becaf6b149
affected

17631e8ca2d3421090e54b39d9a1402091019ba1 before 4c37963d67fb945a59faf53bebe048ca201e44df
affected

17631e8ca2d3421090e54b39d9a1402091019ba1 before 9b5b600e751fae92ba571b015eaf02c9c58e2083
affected

17631e8ca2d3421090e54b39d9a1402091019ba1 before 3d30048958e0d43425f6d4e76565e6249fa71050
affected

Default status
affected

5.13
affected

Any version before 5.13
unaffected

5.15.187
unaffected

6.1.144
unaffected

6.6.97
unaffected

6.12.37
unaffected

6.15.6
unaffected

6.16-rc5
unaffected

References

git.kernel.org/...c/475f89e1f9bde45fc948589e7cde1f5d899ae412

git.kernel.org/...c/5b622e672e49e50c33fc64cd06b05ce76e1de460

git.kernel.org/...c/6358cb9c2a31e23b6b51bfcd7fe2b7becaf6b149

git.kernel.org/...c/4c37963d67fb945a59faf53bebe048ca201e44df

git.kernel.org/...c/9b5b600e751fae92ba571b015eaf02c9c58e2083

git.kernel.org/...c/3d30048958e0d43425f6d4e76565e6249fa71050

cve.org (CVE-2025-38380)

nvd.nist.gov (CVE-2025-38380)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-38380

Support options

Helpdesk Chat, Email, Knowledgebase