Answer in brief
CVE-2025-23157 records a Unknown severity vulnerability in media: venus: hfi_parser: add check to avoid out of bound access. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-23157 records a Unknown severity vulnerability in media: venus: hfi_parser: add check to avoid out of bound access. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1a73374a04e555103e5369429a30999114001dda <e5133a0b25463674903fdc0528e0a29b7267130e || >=1a73374a04e555103e5369429a30999114001dda <2b8b9ea4e26a501eb220ea189e42b4527e65bdfa || >=1a73374a04e555103e5369429a30999114001dda <1ad6aa1464b8a5ce5c194458315021e8d216108e || >=1a73374a04e555103e5369429a30999114001dda <26bbedd06d85770581fda5d78e78539bb088fad1 || >=1a73374a04e555103e5369429a30999114001dda <d4d88ece4ba91df5b02f1d3f599650f9e9fc0f45 || >=1a73374a04e555103e5369429a30999114001dda <53e376178ceacca3ef1795038b22fc9ef45ff1d3 || >=1a73374a04e555103e5369429a30999114001dda <b2541e29d82da8a0df728aadec3e0a8db55d517b || >=1a73374a04e555103e5369429a30999114001dda <cb5be9039f91979f8a2fac29f529f746d7848f3e || >=1a73374a04e555103e5369429a30999114001dda <172bf5a9ef70a399bb227809db78442dc01d9e48 | e5133a0b25463674903fdc0528e0a29b7267130e, 2b8b9ea4e26a501eb220ea189e42b4527e65bdfa, 1ad6aa1464b8a5ce5c194458315021e8d216108e, 26bbedd06d85770581fda5d78e78539bb088fad1, d4d88ece4ba91df5b02f1d3f599650f9e9fc0f45, 53e376178ceacca3ef1795038b22fc9ef45ff1d3, b2541e29d82da8a0df728aadec3e0a8db55d517b, cb5be9039f91979f8a2fac29f529f746d7848f3e, 172bf5a9ef70a399bb227809db78442dc01d9e48 |
| Linux/Linuxgeneric | 4.19 | Not reported |
Published upstream
May 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of bound access There is a possibility that init_codecs is invoked multiple times during manipulated payload from video firmware. In such case, if codecs_count can get incremented to value more than MAX_CODEC_NUM, there can be OOB access. Reset the count so that it always starts from beginning.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1a73374a04e555103e5369429a30999114001dda <e5133a0b25463674903fdc0528e0a29b7267130e || >=1a73374a04e555103e5369429a30999114001dda <2b8b9ea4e26a501eb220ea189e42b4527e65bdfa || >=1a73374a04e555103e5369429a30999114001dda <1ad6aa1464b8a5ce5c194458315021e8d216108e || >=1a73374a04e555103e5369429a30999114001dda <26bbedd06d85770581fda5d78e78539bb088fad1 || >=1a73374a04e555103e5369429a30999114001dda <d4d88ece4ba91df5b02f1d3f599650f9e9fc0f45 || >=1a73374a04e555103e5369429a30999114001dda <53e376178ceacca3ef1795038b22fc9ef45ff1d3 || >=1a73374a04e555103e5369429a30999114001dda <b2541e29d82da8a0df728aadec3e0a8db55d517b || >=1a73374a04e555103e5369429a30999114001dda <cb5be9039f91979f8a2fac29f529f746d7848f3e || >=1a73374a04e555103e5369429a30999114001dda <172bf5a9ef70a399bb227809db78442dc01d9e48 | e5133a0b25463674903fdc0528e0a29b7267130e, 2b8b9ea4e26a501eb220ea189e42b4527e65bdfa, 1ad6aa1464b8a5ce5c194458315021e8d216108e, 26bbedd06d85770581fda5d78e78539bb088fad1, d4d88ece4ba91df5b02f1d3f599650f9e9fc0f45, 53e376178ceacca3ef1795038b22fc9ef45ff1d3, b2541e29d82da8a0df728aadec3e0a8db55d517b, cb5be9039f91979f8a2fac29f529f746d7848f3e, 172bf5a9ef70a399bb227809db78442dc01d9e48 |
| Linux/Linuxgeneric | 4.19 | Not reported |
Published upstream
May 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of bound access There is a possibility that init_codecs is invoked multiple times during manipulated payload from video firmware. In such case, if codecs_count can get incremented to value more than MAX_CODEC_NUM, there can be OOB access. Reset the count so that it always starts from beginning.
Quoted source text, attributed separately from HOL analysis.