The following table lists the changes that have been made to the
CVE-2025-37979 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by 416baaa9-dc9f-4396-8d5f-8c081fb06d67May. 20, 2025
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix sc7280 lpass potential buffer overflow
Case values introduced in commit
5f78e1fb7a3e (“ASoC: qcom: Add driver support for audioreach solution”)
cause out of bounds access in arrays of sc7280 driver data (e.g. in case
of RX_CODEC_DMA_RX_0 in sc7280_snd_hw_params()).Redefine LPASS_MAX_PORTS to consider the maximum possible port id for
q6dsp as sc7280 driver utilizes some of those values.Found by Linux Verification Center (linuxtesting.org) with SVACE.
Added Reference https://git.kernel.org/stable/c/a12c14577882b1f2b4cff0f86265682f16e97b0c Added Reference https://git.kernel.org/stable/c/a31a4934b31faea76e735bab17e63d02fcd8e029 Added Reference https://git.kernel.org/stable/c/b807b7c81a6d066757a94af7b8fa5b6a37e4d0b3 Added Reference https://git.kernel.org/stable/c/c0ce01e0ff8a0d61a7b089ab309cdc12bc527c39 Added Reference https://git.kernel.org/stable/c/d78888853eb53f47ae16cf3aa5d0444d0331b9f8