In the Linux kernel, the following vulnerability has been resolved:
platform/x86: dell-wmi-sysman: Avoid buffer overflow in currentpasswordstore()
If the 'buf' array received from the user contains an empty string, the 'length' variable will be zero. Accessing the 'buf' array element with index 'length - 1' will result in a buffer overflow.
Add a check for an empty string.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8594a123cfa23d708582dc6fb36da34479ef8a5b",
"id": "CVE-2025-38077-3fe8df28",
"deprecated": false,
"target": {
"function": "current_password_store",
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"length": 524.0,
"function_hash": "64199916813402106084291944200556239004"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@60bd13f8c4b3de2c910ae1cdbef85b9bbc9685f5",
"id": "CVE-2025-38077-5b2c6f2a",
"deprecated": false,
"target": {
"function": "current_password_store",
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"length": 524.0,
"function_hash": "64199916813402106084291944200556239004"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f86465626917df3b8bdd2756ec0cc9d179c5af0f",
"id": "CVE-2025-38077-5c66f4b0",
"deprecated": false,
"target": {
"function": "current_password_store",
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"length": 524.0,
"function_hash": "64199916813402106084291944200556239004"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fb7cde625872709b8cedad9b241e0ec3d82fa7d3",
"id": "CVE-2025-38077-5f904364",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"315457531425214205528761832479708430479",
"6707446586014877422154214946586746443",
"27060192538737194607034156348986172783",
"156432068038107089938576925433196552991"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8594a123cfa23d708582dc6fb36da34479ef8a5b",
"id": "CVE-2025-38077-5f9789ae",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"315457531425214205528761832479708430479",
"6707446586014877422154214946586746443",
"27060192538737194607034156348986172783",
"156432068038107089938576925433196552991"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@97066373ffd55bd9af0b512ff3dd1f647620a3dc",
"id": "CVE-2025-38077-ac7d412b",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"315457531425214205528761832479708430479",
"6707446586014877422154214946586746443",
"27060192538737194607034156348986172783",
"156432068038107089938576925433196552991"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@60bd13f8c4b3de2c910ae1cdbef85b9bbc9685f5",
"id": "CVE-2025-38077-bc9e5028",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"315457531425214205528761832479708430479",
"6707446586014877422154214946586746443",
"27060192538737194607034156348986172783",
"156432068038107089938576925433196552991"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f86465626917df3b8bdd2756ec0cc9d179c5af0f",
"id": "CVE-2025-38077-c71163df",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"315457531425214205528761832479708430479",
"6707446586014877422154214946586746443",
"27060192538737194607034156348986172783",
"156432068038107089938576925433196552991"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fb7cde625872709b8cedad9b241e0ec3d82fa7d3",
"id": "CVE-2025-38077-d7bd9660",
"deprecated": false,
"target": {
"function": "current_password_store",
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"length": 524.0,
"function_hash": "64199916813402106084291944200556239004"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4e89a4077490f52cde652d17e32519b666abf3a6",
"id": "CVE-2025-38077-ec0a6072",
"deprecated": false,
"target": {
"function": "current_password_store",
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"length": 524.0,
"function_hash": "64199916813402106084291944200556239004"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@97066373ffd55bd9af0b512ff3dd1f647620a3dc",
"id": "CVE-2025-38077-f23e6216",
"deprecated": false,
"target": {
"function": "current_password_store",
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"length": 524.0,
"function_hash": "64199916813402106084291944200556239004"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4e89a4077490f52cde652d17e32519b666abf3a6",
"id": "CVE-2025-38077-f4046add",
"deprecated": false,
"target": {
"file": "drivers/platform/x86/dell/dell-wmi-sysman/passobj-attributes.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"315457531425214205528761832479708430479",
"6707446586014877422154214946586746443",
"27060192538737194607034156348986172783",
"156432068038107089938576925433196552991"
]
},
"signature_type": "Line"
}
]