In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Validate the size of the received input buffer Add buffer_recv_size to store the size of the received bytes. Validate buffer_recv_size in send_usb_cmd().
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025081627-CVE-2025-38548-6800@gregkh/T