Executive brief
A vulnerability exists in the Linux kernel's Venus video driver, which is used for hardware-accelerated video encoding and decoding on certain platforms. The system fails to properly check the size of data sent by the hardware's firmware, which could allow a malicious or malfunctioning firmware component to access restricted areas of system memory. This could lead to a complete system crash or the unauthorized exposure of sensitive information stored in memory.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the Linux kernel Venus driver (drivers/media/platform/qcom/venus/hfi_msgs.c). The root cause is a lack of validation in the event_seq_changed() handler, which processes a variable number of properties from the Host Firmware Interface (HFI) without verifying the payload size against the actual message length. A local attacker or compromised firmware could provide a property count exceeding the buffer, leading to OOB memory access. This can result in a kernel oops (denial of service) or disclosure of kernel memory. The issue has been patched in multiple stable branches including 6.1.149, 6.6.103, 6.12.43, and 6.15.11.
Affected products
- Linux Linux Kernel 4.13 to 6.15.11
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2025-09-04: advisory: Initial NVD publication date
- 2025-07-03: patched: Mainline kernel patch committed
References
- https://git.kernel.org/stable/c/06d6770ff0d8cc8dfd392329a8cc03e2a83e7289
- https://git.kernel.org/stable/c/6f08bfb5805637419902f3d70069fe17a404545b
- https://git.kernel.org/stable/c/8f274e2b05fdae7a53cee83979202b5ecb49035c
- https://git.kernel.org/stable/c/a3eef5847603cd8a4110587907988c3f93c9605a
- https://git.kernel.org/stable/c/bed4921055dd7bb4d2eea2729852ae18cf97a2c6
- https://git.kernel.org/stable/c/c956c3758510b448b3d4d10d1da8230e8c9bf668
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html