Executive brief
A vulnerability in the Linux kernel's USB Video Class (UVC) driver could allow a local attacker to cause a system crash or potentially access sensitive information from the system's memory. The issue occurs when the system processes specifically formatted video device data, such as from a webcam. This could impact the stability of the operating system or lead to unauthorized data exposure.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel's uvcvideo driver within the uvc_parse_format() function. The root cause is an insufficient check that only ensured a buffer length of at least 3 bytes, while the function subsequently attempts to access the fourth byte (index 3). A local attacker with the ability to provide malicious descriptors (e.g., via a crafted USB device) could trigger this 1-byte out-of-bounds read. This can result in a kernel oops (denial of service) or the leakage of sensitive kernel memory information. The vulnerability has been addressed by updating the validation logic to require a minimum buffer length of 4 bytes.
Affected products
- Linux Linux Kernel 2.6.27 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-06-10: other: Initial patch authored
- 2025-09-04: disclosed: CVE published
- 2025-08-28: patched: Patch committed to stable tree
References
- https://git.kernel.org/stable/c/1e269581b3aa5962fdc52757ab40da286168c087
- https://git.kernel.org/stable/c/424980d33b3f816485513e538610168b03fab9f1
- https://git.kernel.org/stable/c/6d4a7c0b296162354b6fc759a1475b9d57ddfaa6
- https://git.kernel.org/stable/c/782b6a718651eda3478b1824b37a8b3185d2740c
- https://git.kernel.org/stable/c/8343f3fe0b755925f83d60b05e92bf4396879758
- https://git.kernel.org/stable/c/9ad554217c9b945031c73df4e8176a475e2dea57
- https://git.kernel.org/stable/c/a97e062e4ff3dab84a2f1eb811e9eddc6699e2a9