In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-cpro) Validate the size of the received input buffer
Add bufferrecvsize to store the size of the received bytes. Validate bufferrecvsize in sendusbcmd().
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38548.json",
"cna_assigner": "Linux"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38548.json"
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0db770e2922389753ddbd6663a5516a32b97b743",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38548-2748cdce",
"digest": {
"length": 399.0,
"function_hash": "140592509884036790329149387463908457090"
},
"signature_type": "Function",
"target": {
"file": "drivers/hwmon/corsair-cpro.c",
"function": "ccp_raw_event"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0db770e2922389753ddbd6663a5516a32b97b743",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38548-5e2da6e1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"100889771964892691770830143151687906997",
"179874832237574713705104621138790094625",
"118928083873698220056324096121135047560",
"236068381823577171463046476793923656654",
"236394300003463505754356189279202087775",
"242541695960646280499103615975431844954",
"97191819187891982697985857838502560524",
"50397356123254193102778634293795532681",
"1096555769317570328913712470867188625",
"83179079340139023654107077112138897388",
"183370953296247389343096883344054753247"
]
},
"signature_type": "Line",
"target": {
"file": "drivers/hwmon/corsair-cpro.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0db770e2922389753ddbd6663a5516a32b97b743",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-38548-e129635a",
"digest": {
"length": 720.0,
"function_hash": "305952184870419872460348854667137941527"
},
"signature_type": "Function",
"target": {
"file": "drivers/hwmon/corsair-cpro.c",
"function": "send_usb_cmd"
}
}
]