CVE-2025-57983
WordPress vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel was discovered and disclosed on February 26, 2025, identified as CVE-2024-57983. The issue affects the mailbox functionality in the th1520 component, specifically related to memory corruption due to incorrect array sizing. This vulnerability impacts Linux kernel versions from 6.13 up to but not including 6.13.2 (NVD).

Technical details

The vulnerability stems from an implementation flaw in the th1520_mbox_suspend_noirq and th1520_mbox_resume_noirq functions, which are responsible for managing interrupt mask registers in the MBOX ICU0. The array used for storing these registers was incorrectly sized, leading to memory corruption when accessing all four registers. The issue has been classified as CWE-787 (Out-of-bounds Write) with a CVSS v3.1 base score of 7.8 (HIGH), having a vector string of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability can result in memory corruption during suspend and resume operations, potentially leading to system instability or compromise. With a high CVSS score of 7.8, the vulnerability poses significant risks to system confidentiality, integrity, and availability (NVD).

Mitigation and workarounds

A fix has been implemented that corrects the array size to properly accommodate all four interrupt mask registers, preventing memory corruption during suspend and resume operations. The fix is available in Linux kernel version 6.13.2 and later (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12379MEDIUM6.4
  • auxin-elements
NoYesJan 10, 2026
CVE-2025-14555MEDIUM6.4
  • widget-countdown
NoYesJan 10, 2026
CVE-2025-14506MEDIUM6.4
  • convertforce-popup-builder
NoYesJan 10, 2026
CVE-2025-13393MEDIUM4.3
  • featured-image-from-url
NoYesJan 10, 2026
CVE-2025-14579N/AN/A
  • quiz-maker
NoYesJan 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management