CVE-2025-68346

Source
https://cve.org/CVERecord?id=CVE-2025-68346
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68346.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-68346
Downstream
Related
Published
2025-12-24T10:32:39.101Z
Modified
2026-03-20T12:46:23.026375Z
Summary
ALSA: dice: fix buffer overflow in detect_stream_formats()
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: dice: fix buffer overflow in detectstreamformats()

The function detectstreamformats() reads the streamcount value directly from a FireWire device without validating it. This can lead to out-of-bounds writes when a malicious device provides a streamcount value greater than MAX_STREAMS.

Fix by applying the same validation to both TX and RX stream counts in detectstreamformats().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68346.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
58579c056c1c9510ae6695ed8e01ee05bbdcfb23
Fixed
d6280a5b00cad37d9a9a875849e5bf7ed2fe4950
Fixed
3cf854cec0eb371da47ff5fe56eab189d7fa623a
Fixed
4a6ab0f6cc9bdfdfecbf257a46ff4275bd965af4
Fixed
dea3ed2c16f99f46f97b1a090bf80ecdd6972ce0
Fixed
c0a1fe1902ad23e6d48e0f68be1258ccf7a163e6
Fixed
932aa1e80b022419cf9710e970739b7a8794f27c
Fixed
1e1b3207a53e50d5a66289fffc1f7d52cd9c50f9
Fixed
324f3e03e8a85931ce0880654e3c3eb38b0f0bba

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68346.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.18.0
Fixed
5.10.248
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.198
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.63
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.13
Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68346.json"