Linux Kernel SMBUS Block Read Message Length Validation Vulnerability

Vulnerability

A vulnerability in the Linux kernel's I2C Tegra subsystem has been addressed, which involved improper handling of message lengths during SMBUS block read operations. The issue allowed the read process to continue even when the length specified by the device was '0' or exceeded the maximum allowable bytes.

Impact

The vulnerability could lead to incorrect data handling during SMBUS block read operations, potentially causing buffer overflows or other memory-related issues.

Added: Jul 25, 2025, 4:28 PM
Updated: Jul 25, 2025, 4:28 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.