In the Linux kernel, the following vulnerability has been resolved:
media: venus: Add a check for packet size after reading from shared memory
Add a check to ensure that the packet size does not exceed the number of available words after reading the packet header from shared memory. This ensures that the size provided by the firmware is safe to process and prevent potential out-of-bounds memory access.
[
    {
        "id": "CVE-2025-39710-02200b03",
        "target": {
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Line",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f0cbd9386f974d310a0d20a02e4a1323e95ea654",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "35786689626172866272958495055411771126",
                "148800864624583577444293385803215751330",
                "284054582180203477839835777428347669349",
                "152464737557139612207620422957784023210",
                "172055461162118268613425913359557451306",
                "108121979898444934823354809755128684503",
                "37235564796724641663293908361687168572",
                "259530911103116433143675746329145041419"
            ]
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-0a91fbc7",
        "target": {
            "function": "venus_read_queue",
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Function",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ba567c2e52fbcf0e20502746bdaa79e911c2e8cf",
        "digest": {
            "function_hash": "322451788077366790487943853842801844967",
            "length": 1479.0
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-21eb4f7d",
        "target": {
            "function": "venus_read_queue",
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Function",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f0cbd9386f974d310a0d20a02e4a1323e95ea654",
        "digest": {
            "function_hash": "322451788077366790487943853842801844967",
            "length": 1479.0
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-23abadfd",
        "target": {
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Line",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@49befc830daa743e051a65468c05c2ff9e8580e6",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "35786689626172866272958495055411771126",
                "148800864624583577444293385803215751330",
                "284054582180203477839835777428347669349",
                "152464737557139612207620422957784023210",
                "172055461162118268613425913359557451306",
                "108121979898444934823354809755128684503",
                "37235564796724641663293908361687168572",
                "259530911103116433143675746329145041419"
            ]
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-23bb2477",
        "target": {
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Line",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0520c89f6280d2b60ab537d5743601185ee7d8ab",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "35786689626172866272958495055411771126",
                "148800864624583577444293385803215751330",
                "284054582180203477839835777428347669349",
                "152464737557139612207620422957784023210",
                "172055461162118268613425913359557451306",
                "108121979898444934823354809755128684503",
                "37235564796724641663293908361687168572",
                "259530911103116433143675746329145041419"
            ]
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-23f634bc",
        "target": {
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Line",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f5b7a943055a4a106d40a03bacd940e28cc1955f",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "35786689626172866272958495055411771126",
                "148800864624583577444293385803215751330",
                "284054582180203477839835777428347669349",
                "152464737557139612207620422957784023210",
                "172055461162118268613425913359557451306",
                "108121979898444934823354809755128684503",
                "37235564796724641663293908361687168572",
                "259530911103116433143675746329145041419"
            ]
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-2d26c54b",
        "target": {
            "function": "venus_read_queue",
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Function",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f5b7a943055a4a106d40a03bacd940e28cc1955f",
        "digest": {
            "function_hash": "322451788077366790487943853842801844967",
            "length": 1479.0
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-413f9419",
        "target": {
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Line",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ba567c2e52fbcf0e20502746bdaa79e911c2e8cf",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "35786689626172866272958495055411771126",
                "148800864624583577444293385803215751330",
                "284054582180203477839835777428347669349",
                "152464737557139612207620422957784023210",
                "172055461162118268613425913359557451306",
                "108121979898444934823354809755128684503",
                "37235564796724641663293908361687168572",
                "259530911103116433143675746329145041419"
            ]
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-4fcb7f46",
        "target": {
            "function": "venus_read_queue",
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Function",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7638bae4539dcebc3f68fda74ac35d73618ec440",
        "digest": {
            "function_hash": "322451788077366790487943853842801844967",
            "length": 1479.0
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-740df1de",
        "target": {
            "function": "venus_read_queue",
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Function",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@49befc830daa743e051a65468c05c2ff9e8580e6",
        "digest": {
            "function_hash": "322451788077366790487943853842801844967",
            "length": 1479.0
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-994012b6",
        "target": {
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Line",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef09b96665f16f3f0bac4e111160e6f24f1f8791",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "35786689626172866272958495055411771126",
                "148800864624583577444293385803215751330",
                "284054582180203477839835777428347669349",
                "152464737557139612207620422957784023210",
                "172055461162118268613425913359557451306",
                "108121979898444934823354809755128684503",
                "37235564796724641663293908361687168572",
                "259530911103116433143675746329145041419"
            ]
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-a9915c01",
        "target": {
            "function": "venus_read_queue",
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Function",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2d8cea8310a245730816a1fd0c9fa4a5a3bdc68c",
        "digest": {
            "function_hash": "322451788077366790487943853842801844967",
            "length": 1479.0
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-aa5babbc",
        "target": {
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Line",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2d8cea8310a245730816a1fd0c9fa4a5a3bdc68c",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "35786689626172866272958495055411771126",
                "148800864624583577444293385803215751330",
                "284054582180203477839835777428347669349",
                "152464737557139612207620422957784023210",
                "172055461162118268613425913359557451306",
                "108121979898444934823354809755128684503",
                "37235564796724641663293908361687168572",
                "259530911103116433143675746329145041419"
            ]
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-ac7ab044",
        "target": {
            "function": "venus_read_queue",
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Function",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0520c89f6280d2b60ab537d5743601185ee7d8ab",
        "digest": {
            "function_hash": "322451788077366790487943853842801844967",
            "length": 1479.0
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-b88007eb",
        "target": {
            "function": "venus_read_queue",
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Function",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef09b96665f16f3f0bac4e111160e6f24f1f8791",
        "digest": {
            "function_hash": "322451788077366790487943853842801844967",
            "length": 1479.0
        },
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "id": "CVE-2025-39710-edac8351",
        "target": {
            "file": "drivers/media/platform/qcom/venus/hfi_venus.c"
        },
        "signature_type": "Line",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7638bae4539dcebc3f68fda74ac35d73618ec440",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "35786689626172866272958495055411771126",
                "148800864624583577444293385803215751330",
                "284054582180203477839835777428347669349",
                "152464737557139612207620422957784023210",
                "172055461162118268613425913359557451306",
                "108121979898444934823354809755128684503",
                "37235564796724641663293908361687168572",
                "259530911103116433143675746329145041419"
            ]
        },
        "deprecated": false,
        "signature_version": "v1"
    }
]