In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-cpro) Validate the size of the received input buffer
Add bufferrecvsize to store the size of the received bytes. Validate bufferrecvsize in sendusbcmd().
[
{
"signature_type": "Function",
"digest": {
"function_hash": "140592509884036790329149387463908457090",
"length": 399.0
},
"target": {
"file": "drivers/hwmon/corsair-cpro.c",
"function": "ccp_raw_event"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eda5e38cc4dd2dcb422840540374910ef2818494",
"id": "CVE-2025-38548-0f04b974",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"100889771964892691770830143151687906997",
"179874832237574713705104621138790094625",
"118928083873698220056324096121135047560",
"236068381823577171463046476793923656654",
"236394300003463505754356189279202087775",
"242541695960646280499103615975431844954",
"97191819187891982697985857838502560524",
"50397356123254193102778634293795532681",
"1096555769317570328913712470867188625",
"83179079340139023654107077112138897388",
"183370953296247389343096883344054753247"
]
},
"target": {
"file": "drivers/hwmon/corsair-cpro.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eda5e38cc4dd2dcb422840540374910ef2818494",
"id": "CVE-2025-38548-941fb82b",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "305952184870419872460348854667137941527",
"length": 720.0
},
"target": {
"file": "drivers/hwmon/corsair-cpro.c",
"function": "send_usb_cmd"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eda5e38cc4dd2dcb422840540374910ef2818494",
"id": "CVE-2025-38548-e5221b1e",
"deprecated": false,
"signature_version": "v1"
}
]