Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Microsoft donates DocumentDB to the Linux Foundation

      August 25, 2025

      A Week In The Life Of An AI-Augmented Designer

      August 22, 2025

      This week in AI updates: Gemini Code Assist Agent Mode, GitHub’s Agents panel, and more (August 22, 2025)

      August 22, 2025

      Microsoft adds Copilot-powered debugging features for .NET in Visual Studio

      August 21, 2025

      ChatGPT is reportedly scraping Google Search data to answer your questions – here’s how

      August 26, 2025

      The 10 best early Labor Day deals live now: Save on Apple, Samsung and more

      August 26, 2025

      5 rumored Apple iPhone Fold features that have me excited (and frustrated at the same time)

      August 26, 2025

      Forget plug-and-play AI: Here’s what successful AI projects do differently

      August 26, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Log Outgoing HTTP Requests with the Laravel Spy Package

      August 26, 2025
      Recent

      Log Outgoing HTTP Requests with the Laravel Spy Package

      August 26, 2025

      devdojo/auth

      August 26, 2025

      Rust Slices: Cutting Into References the Safe Way

      August 26, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Best AI Girlfriend Simulator [2025 Working Apps and Websites]

      August 25, 2025
      Recent

      Best AI Girlfriend Simulator [2025 Working Apps and Websites]

      August 25, 2025

      8 Best Paid and Free AI Sexting Chat Apps in 2025

      August 25, 2025

      Best AI Anime Art Generator: 7 Best to Use [Free & Premium]

      August 25, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-38348 – “Intersil p54 WiFi Interface Buffer Overflow Vulnerability”

    CVE-2025-38348 – “Intersil p54 WiFi Interface Buffer Overflow Vulnerability”

    July 10, 2025

    CVE ID : CVE-2025-38348

    Published : July 10, 2025, 9:15 a.m. | 4 hours, 51 minutes ago

    Description : In the Linux kernel, the following vulnerability has been resolved:

    wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()

    Robert Morris reported:

    |If a malicious USB device pretends to be an Intersil p54 wifi
    |interface and generates an eeprom_readback message with a large
    |eeprom->v1.len, p54_rx_eeprom_readback() will copy data from the
    |message beyond the end of priv->eeprom.
    |
    |static void p54_rx_eeprom_readback(struct p54_common *priv,
    | struct sk_buff *skb)
    |{
    | struct p54_hdr *hdr = (struct p54_hdr *) skb->data;
    | struct p54_eeprom_lm86 *eeprom = (struct p54_eeprom_lm86 *) hdr->data;
    |
    | if (priv->fw_var >= 0x509) {
    | memcpy(priv->eeprom, eeprom->v2.data,
    | le16_to_cpu(eeprom->v2.len));
    | } else {
    | memcpy(priv->eeprom, eeprom->v1.data,
    | le16_to_cpu(eeprom->v1.len));
    | }
    | […]

    The eeprom->v{1,2}.len is set by the driver in p54_download_eeprom().
    The device is supposed to provide the same length back to the driver.
    But yes, it’s possible (like shown in the report) to alter the value
    to something that causes a crash/panic due to overrun.

    This patch addresses the issue by adding the size to the common device
    context, so p54_rx_eeprom_readback no longer relies on possibly tampered
    values… That said, it also checks if the “firmware” altered the value
    and no longer copies them.

    The one, small saving grace is: Before the driver tries to read the eeprom,
    it needs to upload >a
    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-38347 – F2FS Inline Data Corruption Denial of Service (DoS) Vulnerability
    Next Article CVE-2025-38342 – Linux Kernel Out-of-Bounds Vulnerability in software_node_get_reference_args

    Related Posts

    Development

    Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing

    August 26, 2025
    Development

    Buffalo Police Detective Indicted for Attempted Purchases on Genesis Market

    August 26, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    PerfektBlue Bluetooth leads to RCE

    Security

    Preventing Zero-Click AI Threats: Insights from EchoLeak

    Security

    CVE-2025-4801 – Apache HTTP Server Command Injection

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-54226 – Adobe InDesign Use After Free Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    News & Updates

    Does The Elder Scrolls 4: Oblivion Remastered support cross saves?

    April 23, 2025

    Bethesda has shadow-dropped the long-awaited remaster of The Elder Scrolls 4: Oblivion, but does this…

    Microsoft Enables Hotpatching by Default for Windows Quality Updates in Autopatch

    June 25, 2025

    Doom 64 EX+ is an improved modern version of Doom64EX

    May 11, 2025

    CISA warns of ConnectWise ScreenConnect bug exploited in attacks

    June 3, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.