CVE-2025-38548 – Corsair CPro Buffer Overflow Vulnerability

The following table lists the changes that have been made to the
CVE-2025-38548 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 16, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    hwmon: (corsair-cpro) Validate the size of the received input buffer

    Add buffer_recv_size to store the size of the received bytes.
    Validate buffer_recv_size in send_usb_cmd().

    Added Reference https://git.kernel.org/stable/c/0db770e2922389753ddbd6663a5516a32b97b743
    Added Reference https://git.kernel.org/stable/c/2771d2ee3d95700f34e1e4df6a445c90565cd4e9
    Added Reference https://git.kernel.org/stable/c/3c4bdc8a852e446080adc8ceb90ddd67a56e1bb8
    Added Reference https://git.kernel.org/stable/c/495a4f0dce9c8c4478c242209748f1ee9e4d5820
    Added Reference https://git.kernel.org/stable/c/eda5e38cc4dd2dcb422840540374910ef2818494
Share the Post:

Related Posts