« Volver al listado

CVE-2025-71197

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

w1: therm: Fix off-by-one buffer overflow in alarms_store

The sysfs buffer passed to alarms_store() is allocated with 'size + 1' bytes and a NUL terminator is appended. However, the 'size' argument does not account for this extra byte. The original code then allocated 'size' bytes and used strcpy() to copy 'buf', which always writes one byte past the allocated buffer since strcpy() copies until the NUL terminator at index 'size'.

Fix this by parsing the 'buf' parameter directly using simple_strtoll() without allocating any intermediate memory or string copying. This removes the overflow while simplifying the code.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-71197",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e2c94d6f572079511945e64537eb1218643f2e68",
              "lessThan": "49ff9b4b9deacbefa6654a0a2bcaf910c9de7e95",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e2c94d6f572079511945e64537eb1218643f2e68",
              "lessThan": "060b08d72a38b158a7f850d4b83c17c2969e0f6b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e2c94d6f572079511945e64537eb1218643f2e68",
              "lessThan": "b3fc3e1f04dcc7c41787bbf08a6e0d2728e022cf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e2c94d6f572079511945e64537eb1218643f2e68",
              "lessThan": "6a5820ecfa5a76c3d3e154802c8c15f391ef442e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e2c94d6f572079511945e64537eb1218643f2e68",
              "lessThan": "6fd6d2a8e41b7f544a4d26cbd60bedf9c67893a0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e2c94d6f572079511945e64537eb1218643f2e68",
              "lessThan": "e6b2609af21b5cccc9559339591b8a2cbf884169",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e2c94d6f572079511945e64537eb1218643f2e68",
              "lessThan": "761fcf46a1bd797bd32d23f3ea0141ffd437668a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/w1/slaves/w1_therm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.249",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.199",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.162",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.122",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.68",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.8",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/w1/slaves/w1_therm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-02-04T17:16:11.633",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/060b08d72a38b158a7f850d4b83c17c2969e0f6b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/49ff9b4b9deacbefa6654a0a2bcaf910c9de7e95",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6a5820ecfa5a76c3d3e154802c8c15f391ef442e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6fd6d2a8e41b7f544a4d26cbd60bedf9c67893a0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/761fcf46a1bd797bd32d23f3ea0141ffd437668a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b3fc3e1f04dcc7c41787bbf08a6e0d2728e022cf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e6b2609af21b5cccc9559339591b8a2cbf884169",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nw1: therm: Fix off-by-one buffer overflow in alarms_store\n\nThe sysfs buffer passed to alarms_store() is allocated with 'size + 1'\nbytes and a NUL terminator is appended. However, the 'size' argument\ndoes not account for this extra byte. The original code then allocated\n'size' bytes and used strcpy() to copy 'buf', which always writes one\nbyte past the allocated buffer since strcpy() copies until the NUL\nterminator at index 'size'.\n\nFix this by parsing the 'buf' parameter directly using simple_strtoll()\nwithout allocating any intermediate memory or string copying. This\nremoves the overflow while simplifying the code."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nw1: therm: Corrección de desbordamiento de búfer por un byte en alarms_store\n\nEl búfer sysfs pasado a alarms_store() se asigna con 'size + 1' bytes y se añade un terminador NUL. Sin embargo, el argumento 'size' no tiene en cuenta este byte adicional. El código original entonces asignaba 'size' bytes y usaba strcpy() para copiar 'buf', lo que siempre escribe un byte más allá del búfer asignado ya que strcpy() copia hasta el terminador NUL en el índice 'size'.\n\nEsto se soluciona analizando el parámetro 'buf' directamente usando simple_strtoll() sin asignar ninguna memoria intermedia ni copiar cadenas. Esto elimina el desbordamiento mientras simplifica el código."
    }
  ],
  "lastModified": "2026-07-14T13:18:05.637",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}