CVE-2025-71136

Source
https://cve.org/CVERecord?id=CVE-2025-71136
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71136.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-71136
Downstream
Related
Published
2026-01-14T15:07:50.568Z
Modified
2026-03-12T04:32:19.601735Z
Summary
media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status()
Details

In the Linux kernel, the following vulnerability has been resolved:

media: adv7842: Avoid possible out-of-bounds array accesses in adv7842cplog_status()

It's possible for cpread() and hdmiread() to return -EIO. Those values are further used as indexes for accessing arrays.

Fix that by checking return values where it's needed.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71136.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a89bcd4c6c2023615a89001b5a11b0bb77eb9491
Fixed
f81ee181cb036d046340c213091b69d9a8701a76
Fixed
f913b9a2ccd6114b206b9e91dae5e3dc13a415a0
Fixed
d6a22a4a96e4dfe6897cb3532d2b3016d87706f0
Fixed
a73881ae085db5702d8b13e2fc9f78d51c723d3f
Fixed
60dde0960e3ead8a9569f6c494d90d0232ac0983
Fixed
b693d48a6ed0cd09171103ad418e4a693203d6e4
Fixed
8163419e3e05d71dcfa8fb49c8fdf8d76908fe51

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71136.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.12.0
Fixed
5.10.248
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.198
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.64
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71136.json"