In the Linux kernel, the following vulnerability has been resolved:
ALSA: dice: fix buffer overflow in detect_stream_formats()
The function detect_stream_formats() reads the stream_count value directly
from a FireWire device without validating it. This can lead to
out-of-bounds writes when a malicious device provides a stream_count value
greater than MAX_STREAMS.
Fix by applying the same validation to both TX and RX stream counts in
detect_stream_formats().
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-24 11:15
Updated : 2026-06-17 09:58
NVD link : CVE-2025-68346
Mitre link : CVE-2025-68346
CVE.ORG link : CVE-2025-68346
JSON object : View
Products Affected
No product.
CWE
No CWE.
