In the Linux kernel, the following vulnerability has been resolved:
usb: typec: altmodes/displayport: do not index invalid pin_assignments
A poorly implemented DisplayPort Alt Mode port partner can indicate that its pin assignment capabilities are greater than the maximum value, DPPINASSIGNF. In this case, calls to pinassignment_show will cause a BRK exception due to an out of bounds array access.
Prevent for loop in pinassignmentshow from accessing invalid values in pinassignments by adding DPPINASSIGNMAX value in typecdp.h and using i < DPPINASSIGNMAX as a loop condition.
[
{
"id": "CVE-2025-38391-03423b51",
"deprecated": false,
"digest": {
"length": 590.0,
"function_hash": "137262048701576009193293429654800586291"
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c",
"function": "pin_assignment_show"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@45e9444b3b97eaf51a5024f1fea92f44f39b50c6",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38391-0fba45f5",
"deprecated": false,
"digest": {
"line_hashes": [
"22607749272792709159311483836492810847",
"192271691880387877456811388698662446627",
"45314020526360658639978429553506926566",
"271317181995527661536294339015942314994"
],
"threshold": 0.9
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@621d5a3ef0231ab242f2d31eecec40c38ca609c5",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-1a2a58cc",
"deprecated": false,
"digest": {
"line_hashes": [
"22607749272792709159311483836492810847",
"192271691880387877456811388698662446627",
"45314020526360658639978429553506926566",
"271317181995527661536294339015942314994"
],
"threshold": 0.9
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@45e9444b3b97eaf51a5024f1fea92f44f39b50c6",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-1eecd184",
"deprecated": false,
"digest": {
"line_hashes": [
"225355001827243902996313103016082342156",
"195365578213282193270875044404156350008",
"100026723696653192211359713991068147000",
"146002046619075620690633299373124254155"
],
"threshold": 0.9
},
"target": {
"file": "include/linux/usb/typec_dp.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@621d5a3ef0231ab242f2d31eecec40c38ca609c5",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-2a72519d",
"deprecated": false,
"digest": {
"length": 590.0,
"function_hash": "137262048701576009193293429654800586291"
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c",
"function": "pin_assignment_show"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@114a977e0f6bf278e05eade055e13fc271f69cf7",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38391-3485c4ed",
"deprecated": false,
"digest": {
"line_hashes": [
"225355001827243902996313103016082342156",
"195365578213282193270875044404156350008",
"100026723696653192211359713991068147000",
"146002046619075620690633299373124254155"
],
"threshold": 0.9
},
"target": {
"file": "include/linux/usb/typec_dp.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47cb5d26f61d80c805d7de4106451153779297a1",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-368160d7",
"deprecated": false,
"digest": {
"line_hashes": [
"22607749272792709159311483836492810847",
"192271691880387877456811388698662446627",
"45314020526360658639978429553506926566",
"271317181995527661536294339015942314994"
],
"threshold": 0.9
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c93bc959788ed9a1af7df57cb539837bdf790cee",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-42875b2e",
"deprecated": false,
"digest": {
"length": 590.0,
"function_hash": "137262048701576009193293429654800586291"
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c",
"function": "pin_assignment_show"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f535517b5611b7221ed478527e4b58e29536ddf",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38391-4b22705c",
"deprecated": false,
"digest": {
"line_hashes": [
"22607749272792709159311483836492810847",
"192271691880387877456811388698662446627",
"45314020526360658639978429553506926566",
"271317181995527661536294339015942314994"
],
"threshold": 0.9
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f535517b5611b7221ed478527e4b58e29536ddf",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-4b4d823f",
"deprecated": false,
"digest": {
"line_hashes": [
"225355001827243902996313103016082342156",
"195365578213282193270875044404156350008",
"100026723696653192211359713991068147000",
"146002046619075620690633299373124254155"
],
"threshold": 0.9
},
"target": {
"file": "include/linux/usb/typec_dp.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f535517b5611b7221ed478527e4b58e29536ddf",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-5209916c",
"deprecated": false,
"digest": {
"length": 590.0,
"function_hash": "137262048701576009193293429654800586291"
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c",
"function": "pin_assignment_show"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5581e694d3a1c2f32c5a51d745c55b107644e1f8",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38391-5a50b54c",
"deprecated": false,
"digest": {
"line_hashes": [
"22607749272792709159311483836492810847",
"192271691880387877456811388698662446627",
"45314020526360658639978429553506926566",
"271317181995527661536294339015942314994"
],
"threshold": 0.9
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@114a977e0f6bf278e05eade055e13fc271f69cf7",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-7d0b1ae4",
"deprecated": false,
"digest": {
"line_hashes": [
"225355001827243902996313103016082342156",
"195365578213282193270875044404156350008",
"100026723696653192211359713991068147000",
"146002046619075620690633299373124254155"
],
"threshold": 0.9
},
"target": {
"file": "include/linux/usb/typec_dp.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@114a977e0f6bf278e05eade055e13fc271f69cf7",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-83108ac4",
"deprecated": false,
"digest": {
"length": 590.0,
"function_hash": "137262048701576009193293429654800586291"
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c",
"function": "pin_assignment_show"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c93bc959788ed9a1af7df57cb539837bdf790cee",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38391-8445c7cd",
"deprecated": false,
"digest": {
"line_hashes": [
"22607749272792709159311483836492810847",
"192271691880387877456811388698662446627",
"45314020526360658639978429553506926566",
"271317181995527661536294339015942314994"
],
"threshold": 0.9
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47cb5d26f61d80c805d7de4106451153779297a1",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-a44fc884",
"deprecated": false,
"digest": {
"length": 590.0,
"function_hash": "137262048701576009193293429654800586291"
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c",
"function": "pin_assignment_show"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47cb5d26f61d80c805d7de4106451153779297a1",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2025-38391-c3060443",
"deprecated": false,
"digest": {
"line_hashes": [
"225355001827243902996313103016082342156",
"195365578213282193270875044404156350008",
"100026723696653192211359713991068147000",
"146002046619075620690633299373124254155"
],
"threshold": 0.9
},
"target": {
"file": "include/linux/usb/typec_dp.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c93bc959788ed9a1af7df57cb539837bdf790cee",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-c3c42172",
"deprecated": false,
"digest": {
"line_hashes": [
"22607749272792709159311483836492810847",
"192271691880387877456811388698662446627",
"45314020526360658639978429553506926566",
"271317181995527661536294339015942314994"
],
"threshold": 0.9
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5581e694d3a1c2f32c5a51d745c55b107644e1f8",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-e2668212",
"deprecated": false,
"digest": {
"line_hashes": [
"225355001827243902996313103016082342156",
"195365578213282193270875044404156350008",
"100026723696653192211359713991068147000",
"146002046619075620690633299373124254155"
],
"threshold": 0.9
},
"target": {
"file": "include/linux/usb/typec_dp.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5581e694d3a1c2f32c5a51d745c55b107644e1f8",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-ef409793",
"deprecated": false,
"digest": {
"line_hashes": [
"225355001827243902996313103016082342156",
"195365578213282193270875044404156350008",
"100026723696653192211359713991068147000",
"146002046619075620690633299373124254155"
],
"threshold": 0.9
},
"target": {
"file": "include/linux/usb/typec_dp.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@45e9444b3b97eaf51a5024f1fea92f44f39b50c6",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2025-38391-f4f316ac",
"deprecated": false,
"digest": {
"length": 590.0,
"function_hash": "137262048701576009193293429654800586291"
},
"target": {
"file": "drivers/usb/typec/altmodes/displayport.c",
"function": "pin_assignment_show"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@621d5a3ef0231ab242f2d31eecec40c38ca609c5",
"signature_version": "v1",
"signature_type": "Function"
}
]