---
id: CVE-2025-71197
title: 'w1: therm: Fix off-by-one buffer overflow in alarms_store'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  w1: therm: Fix off-by-one buffer overflow in alarms_store

  The sysfs buffer passed to alarms_store() is allocated with 'size + 1'
  bytes and a NUL terminator is appended…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= e2c94d6f572079511945e64537eb1218643f2e68 <
    49ff9b4b9deacbefa6654a0a2bcaf910c9de7e95
  - >-
    Linux >= e2c94d6f572079511945e64537eb1218643f2e68 <
    060b08d72a38b158a7f850d4b83c17c2969e0f6b
  - >-
    Linux >= e2c94d6f572079511945e64537eb1218643f2e68 <
    b3fc3e1f04dcc7c41787bbf08a6e0d2728e022cf
  - >-
    Linux >= e2c94d6f572079511945e64537eb1218643f2e68 <
    6a5820ecfa5a76c3d3e154802c8c15f391ef442e
  - >-
    Linux >= e2c94d6f572079511945e64537eb1218643f2e68 <
    6fd6d2a8e41b7f544a4d26cbd60bedf9c67893a0
  - >-
    Linux >= e2c94d6f572079511945e64537eb1218643f2e68 <
    e6b2609af21b5cccc9559339591b8a2cbf884169
  - >-
    Linux >= e2c94d6f572079511945e64537eb1218643f2e68 <
    761fcf46a1bd797bd32d23f3ea0141ffd437668a
  - Linux 5.8
published: '2026-02-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:44:14.638Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-71197'
references:
  - url: 'https://git.kernel.org/stable/c/49ff9b4b9deacbefa6654a0a2bcaf910c9de7e95'
  - url: 'https://git.kernel.org/stable/c/060b08d72a38b158a7f850d4b83c17c2969e0f6b'
  - url: 'https://git.kernel.org/stable/c/b3fc3e1f04dcc7c41787bbf08a6e0d2728e022cf'
  - url: 'https://git.kernel.org/stable/c/6a5820ecfa5a76c3d3e154802c8c15f391ef442e'
  - url: 'https://git.kernel.org/stable/c/6fd6d2a8e41b7f544a4d26cbd60bedf9c67893a0'
  - url: 'https://git.kernel.org/stable/c/e6b2609af21b5cccc9559339591b8a2cbf884169'
  - url: 'https://git.kernel.org/stable/c/761fcf46a1bd797bd32d23f3ea0141ffd437668a'
tags:
  - cve.org
epss: 0.00208
epssPercentile: 0.09636
ingestedAt: '2026-09-08T15:33:26.994Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

w1: therm: Fix off-by-one buffer overflow in alarms_store

The sysfs buffer passed to alarms_store() is allocated with 'size + 1'
bytes and a NUL terminator is appended. However, the 'size' argument
does not account for this extra byte. The original code then allocated
'size' bytes and used strcpy() to copy 'buf', which always writes one
byte past the allocated buffer since strcpy() copies until the NUL
terminator at index 'size'.

Fix this by parsing the 'buf' parameter directly using simple_strtoll()
without allocating any intermediate memory or string copying. This
removes the overflow while simplifying the code.

## Affected

- `Linux >= e2c94d6f572079511945e64537eb1218643f2e68 < 49ff9b4b9deacbefa6654a0a2bcaf910c9de7e95`
- `Linux >= e2c94d6f572079511945e64537eb1218643f2e68 < 060b08d72a38b158a7f850d4b83c17c2969e0f6b`
- `Linux >= e2c94d6f572079511945e64537eb1218643f2e68 < b3fc3e1f04dcc7c41787bbf08a6e0d2728e022cf`
- `Linux >= e2c94d6f572079511945e64537eb1218643f2e68 < 6a5820ecfa5a76c3d3e154802c8c15f391ef442e`
- `Linux >= e2c94d6f572079511945e64537eb1218643f2e68 < 6fd6d2a8e41b7f544a4d26cbd60bedf9c67893a0`
- `Linux >= e2c94d6f572079511945e64537eb1218643f2e68 < e6b2609af21b5cccc9559339591b8a2cbf884169`
- `Linux >= e2c94d6f572079511945e64537eb1218643f2e68 < 761fcf46a1bd797bd32d23f3ea0141ffd437668a`
- `Linux 5.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
