In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Add basic validation for RAS header
If RAS header read from EEPROM is corrupted, it could result in trying to allocate huge memory for reading the records. Add some validation to header fields.
[
{
"id": "CVE-2025-38426-437ec7cd",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_ras_eeprom.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5df0d6addb7e9b6f71f7162d1253762a5be9138e",
"deprecated": false,
"digest": {
"line_hashes": [
"36677313770406776751056327079346788307",
"174594068661668646286001389455750248885",
"39719756751650100904788671554782527609",
"323147932859695541125912426719535378226",
"319632396120389871258165995689660969964",
"147148077146536093442055702628130531805",
"25618780706446402939600052992532091656",
"123809179598244867296607881597859665918",
"53477078126606848967044065018526120094",
"201390794513535806791159061016124779708",
"169755203199958297649273871845119729813",
"142328612334580512473013318852075758819",
"72902198110221626447074096466121993077"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2025-38426-d2ea2994",
"target": {
"function": "amdgpu_ras_eeprom_init",
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_ras_eeprom.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5df0d6addb7e9b6f71f7162d1253762a5be9138e",
"deprecated": false,
"digest": {
"length": 1356.0,
"function_hash": "198718214871312455388115478572348495420"
},
"signature_type": "Function"
},
{
"id": "CVE-2025-38426-e34805a7",
"target": {
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_ras_eeprom.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b52f52bc5ba9feb026c0be600f8ac584fd12d187",
"deprecated": false,
"digest": {
"line_hashes": [
"36677313770406776751056327079346788307",
"174594068661668646286001389455750248885",
"39719756751650100904788671554782527609",
"323147932859695541125912426719535378226",
"319632396120389871258165995689660969964",
"147148077146536093442055702628130531805",
"25618780706446402939600052992532091656",
"123809179598244867296607881597859665918",
"53477078126606848967044065018526120094",
"201390794513535806791159061016124779708",
"169755203199958297649273871845119729813",
"142328612334580512473013318852075758819",
"72902198110221626447074096466121993077"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2025-38426-f1b1a90d",
"target": {
"function": "amdgpu_ras_eeprom_init",
"file": "drivers/gpu/drm/amd/amdgpu/amdgpu_ras_eeprom.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b52f52bc5ba9feb026c0be600f8ac584fd12d187",
"deprecated": false,
"digest": {
"length": 1356.0,
"function_hash": "198718214871312455388115478572348495420"
},
"signature_type": "Function"
}
]