SB2025072729 - Out-of-bounds read in Linux kernel typec altmodes driver
Published: July 27, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2025-38391)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the pin_assignment_show() function in drivers/usb/typec/altmodes/displayport.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/114a977e0f6bf278e05eade055e13fc271f69cf7
- https://git.kernel.org/stable/c/2f535517b5611b7221ed478527e4b58e29536ddf
- https://git.kernel.org/stable/c/45e9444b3b97eaf51a5024f1fea92f44f39b50c6
- https://git.kernel.org/stable/c/47cb5d26f61d80c805d7de4106451153779297a1
- https://git.kernel.org/stable/c/5581e694d3a1c2f32c5a51d745c55b107644e1f8
- https://git.kernel.org/stable/c/621d5a3ef0231ab242f2d31eecec40c38ca609c5
- https://git.kernel.org/stable/c/af4db5a35a4ef7a68046883bfd12468007db38f1
- https://git.kernel.org/stable/c/c93bc959788ed9a1af7df57cb539837bdf790cee