CVE-2025-68346
Last modified
CVE-2025-68346 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ALSA: dice: fix buffer overflow in detect_stream_formats() The function detect_stream_formats() reads the stream_count value directly from a FireWire device without validating it. This can lead to out-of-bounds writes when a malicious device provides a stream_count value greater than MAX_STREAMS. Fix by applying the same validation to both TX and RX stream counts in detect_stream_formats().. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: dice: fix buffer overflow in detect_stream_formats() The function detect_stream_formats() reads the stream_count value directly from a FireWire device without validating it. This can lead to out-of-bounds writes when a malicious device provides a stream_count value greater than MAX_STREAMS. Fix by applying the same validation to both TX and RX stream counts in detect_stream_formats().
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 58579c056c1c9510ae6695ed8e01ee05bbdcfb23, < d6280a5b00cad37d9a9a875849e5bf7ed2fe4950; >= 58579c056c1c9510ae6695ed8e01ee05bbdcfb23, < 3cf854cec0eb371da47ff5fe56eab189d7fa623a; >= 58579c056c1c9510ae6695ed8e01ee05bbdcfb23, < 4a6ab0f6cc9bdfdfecbf257a46ff4275bd965af4; >= 58579c056c1c9510ae6695ed8e01ee05bbdcfb23, < dea3ed2c16f99f46f97b1a090bf80ecdd6972ce0; >= 58579c056c1c9510ae6695ed8e01ee05bbdcfb23, < c0a1fe1902ad23e6d48e0f68be1258ccf7a163e6; >= 58579c056c1c9510ae6695ed8e01ee05bbdcfb23, < 932aa1e80b022419cf9710e970739b7a8794f27c; >= 58579c056c1c9510ae6695ed8e01ee05bbdcfb23, < 1e1b3207a53e50d5a66289fffc1f7d52cd9c50f9; >= 58579c056c1c9510ae6695ed8e01ee05bbdcfb23, < 324f3e03e8a85931ce0880654e3c3eb38b0f0bba |
| Linux | Linux | 4.18 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68346?
How severe is CVE-2025-68346?
How do I fix CVE-2025-68346?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68340In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-68341In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-68342In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68343In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68344In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68345In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68347In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68348In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68349In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2025-6835A vulnerability was found in code-projects Library System 1.…9.8
- CVE-2025-68350In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68351In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2025-68346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
