Junglewise Threat Intelligence

CVE-2025-38693: Linux Kernel null pointer dereference in w7090p DVB tuner driver

CVE-2025-38693 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's digital video broadcasting (DVB) component could allow a local user to crash the system. The issue exists in the w7090p tuner driver, which is used to manage certain television tuner hardware. By providing specially crafted input to the driver, an attacker can trigger a system crash (denial of service), potentially disrupting operations or requiring a manual reboot.

Technical details

A null pointer dereference vulnerability exists in the Linux kernel's DVB frontend driver for w7090p (specifically within dib7000p.c). The functions w7090p_tuner_write_serpar and w7090p_tuner_read_serpar fail to properly validate the length of user-controlled I2C messages. If a user provides a message where the buffer is null and the length is zero, subsequent code attempts to access indices (such as buf[2]) without sufficient sanity checks, leading to a kernel panic. The fix introduces explicit length checks (msg[0].len < 3 for writes and similar checks for reads) to ensure the buffer contains expected data before access. This is a local attack requiring basic user privileges.

Affected products

  • Linux Linux Kernel 2.6.39 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-06-15: other: Patch authored
  • 2025-09-04: disclosed: CVE published
  • 2025-08-28: patched: Patch committed to stable branches

References

Related threats