Junglewise Threat Intelligence

CVE-2025-38679: Linux Kernel Venus driver out-of-bounds read in HFI message parsing

CVE-2025-38679 · Severity: high · CVSS 7.3 · Published 2025-09-04

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's Venus video driver, which is used for hardware-accelerated video encoding and decoding on certain platforms. The system fails to properly check the size of data sent by the hardware's firmware, which could allow a malicious or malfunctioning firmware component to access restricted areas of system memory. This could lead to a complete system crash or the unauthorized exposure of sensitive information stored in memory.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the Linux kernel Venus driver (drivers/media/platform/qcom/venus/hfi_msgs.c). The root cause is a lack of validation in the event_seq_changed() handler, which processes a variable number of properties from the Host Firmware Interface (HFI) without verifying the payload size against the actual message length. A local attacker or compromised firmware could provide a property count exceeding the buffer, leading to OOB memory access. This can result in a kernel oops (denial of service) or disclosure of kernel memory. The issue has been patched in multiple stable branches including 6.1.149, 6.6.103, 6.12.43, and 6.15.11.

Affected products

  • Linux Linux Kernel 4.13 to 6.15.11
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-09-04: advisory: Initial NVD publication date
  • 2025-07-03: patched: Mainline kernel patch committed

References

Related threats