CVE-2025-71231

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode The local variable 'i' is initialized with -EINVAL, but the for loop immediately overwrites it and -EINVAL is never returned. If no empty compression mode can be found, the function would return the out-of-bounds index IAA_COMP_MODES_MAX, which would cause an invalid array access in add_iaa_compression_mode(). Fix both issues by returning either a valid index or -EINVAL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

18 Mar 2026, 17:18

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/48329301969f6d21b2ef35f678e40f72b59eac94 - () https://git.kernel.org/stable/c/48329301969f6d21b2ef35f678e40f72b59eac94 - Patch
References () https://git.kernel.org/stable/c/c77b33b58512708bd5603f48465f018c8b748847 - () https://git.kernel.org/stable/c/c77b33b58512708bd5603f48465f018c8b748847 - Patch
References () https://git.kernel.org/stable/c/d75207465eed20bc9b0daa4a0927de9568996067 - () https://git.kernel.org/stable/c/d75207465eed20bc9b0daa4a0927de9568996067 - Patch
References () https://git.kernel.org/stable/c/de16f5bca05cace238d237791ed1b6e9d22dab60 - () https://git.kernel.org/stable/c/de16f5bca05cace238d237791ed1b6e9d22dab60 - Patch

23 Feb 2026, 04:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/48329301969f6d21b2ef35f678e40f72b59eac94 -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: crypto: iaa - Corrección de índice fuera de límites en find_empty_iaa_compression_mode La variable local 'i' se inicializa con -EINVAL, pero el bucle for la sobrescribe inmediatamente y -EINVAL nunca se devuelve. Si no se encuentra ningún modo de compresión vacío, la función devolvería el índice fuera de límites IAA_COMP_MODES_MAX, lo que causaría un acceso a array inválido en add_iaa_compression_mode(). Se corrigen ambos problemas devolviendo un índice válido o -EINVAL.

18 Feb 2026, 16:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 16:22

Updated : 2026-03-18 17:18


NVD link : CVE-2025-71231

Mitre link : CVE-2025-71231

CVE.ORG link : CVE-2025-71231


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read