Junglewise Threat Intelligence

CVE-2025-38680: Linux Kernel out-of-bounds read in uvcvideo uvc_parse_format

CVE-2025-38680 · Severity: high · CVSS 7.1 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB Video Class (UVC) driver could allow a local attacker to cause a system crash or potentially access sensitive information from the system's memory. The issue occurs when the system processes specifically formatted video device data, such as from a webcam. This could impact the stability of the operating system or lead to unauthorized data exposure.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's uvcvideo driver within the uvc_parse_format() function. The root cause is an insufficient check that only ensured a buffer length of at least 3 bytes, while the function subsequently attempts to access the fourth byte (index 3). A local attacker with the ability to provide malicious descriptors (e.g., via a crafted USB device) could trigger this 1-byte out-of-bounds read. This can result in a kernel oops (denial of service) or the leakage of sensitive kernel memory information. The vulnerability has been addressed by updating the validation logic to require a minimum buffer length of 4 bytes.

Affected products

  • Linux Linux Kernel 2.6.27 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-06-10: other: Initial patch authored
  • 2025-09-04: disclosed: CVE published
  • 2025-08-28: patched: Patch committed to stable tree

References

Related threats