In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events The DSP… (CVE-2025-68347)
A buffer overflow vulnerability in the Linux kernel ALSA firewire-motu driver was resolved. The issue occurred in the hwdep_read() function for DSP events, where more bytes could be written to a user buffer than requested if the buffer was smaller than the event header size (8 bytes). The fix clamps the copy size to the user-requested length, preventing overflow.
AI Analysis
Technical Summary
CVE-2025-68347 describes a buffer overflow in the ALSA firewire-motu driver within the Linux kernel. Specifically, the DSP event handling code in hwdep_read() could write beyond the bounds of a user-provided buffer if it was smaller than 8 bytes, the size of the event header. This vulnerability was addressed by using min_t() to limit the number of bytes copied to the size requested by the user, ensuring no overflow occurs.
Potential Impact
The vulnerability allows local attackers with limited privileges to cause a buffer overflow, potentially leading to confidentiality, integrity, and availability impacts on the affected system. The CVSS vector indicates high impact on confidentiality, integrity, and availability, but exploitation requires local access with low privileges and no user interaction.
Mitigation Recommendations
A fix is available and has been applied in the Linux kernel to clamp the copy size in hwdep_read() for DSP events. Users and administrators should update to the fixed Linux kernel version that includes this patch to remediate the vulnerability.
In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events The DSP… (CVE-2025-68347)
Description
A buffer overflow vulnerability in the Linux kernel ALSA firewire-motu driver was resolved. The issue occurred in the hwdep_read() function for DSP events, where more bytes could be written to a user buffer than requested if the buffer was smaller than the event header size (8 bytes). The fix clamps the copy size to the user-requested length, preventing overflow.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-68347 describes a buffer overflow in the ALSA firewire-motu driver within the Linux kernel. Specifically, the DSP event handling code in hwdep_read() could write beyond the bounds of a user-provided buffer if it was smaller than 8 bytes, the size of the event header. This vulnerability was addressed by using min_t() to limit the number of bytes copied to the size requested by the user, ensuring no overflow occurs.
Potential Impact
The vulnerability allows local attackers with limited privileges to cause a buffer overflow, potentially leading to confidentiality, integrity, and availability impacts on the affected system. The CVSS vector indicates high impact on confidentiality, integrity, and availability, but exploitation requires local access with low privileges and no user interaction.
Mitigation Recommendations
A fix is available and has been applied in the Linux kernel to clamp the copy size in hwdep_read() for DSP events. Users and administrators should update to the fixed Linux kernel version that includes this patch to remediate the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h6xr-332m-px9v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-68347"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d29c2644c7f8477c74
Added to database: 07/30/2026, 15:50:42 UTC
Last enriched: 07/30/2026, 18:54:40 UTC
Last updated: 08/07/2026, 00:55:55 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.