Executive brief
A vulnerability in the Linux kernel's digital video broadcasting (DVB) driver could allow a local user to crash the system. The issue exists in the DiB7090P frontend driver, which is used to manage certain television tuner hardware. An attacker with local access could trigger a system failure (kernel crash), leading to a denial of service.
Technical details
A NULL pointer dereference vulnerability exists in the dib7090p_rw_on_apb() function within drivers/media/dvb-frontends/dib7000p.c. The root cause is a lack of sanity checking on user-controlled I2C message lengths (msg[0].len and msg[1].len). When a user provides a message with a length of zero or insufficient size, the driver attempts to access buffer offsets (e.g., msg[0].buf[2]) without verifying the buffer is valid or large enough, leading to a kernel oops. This can be exploited by a local attacker with permissions to interact with the media subsystem to cause a denial of service. Patches have been released across multiple stable kernel branches to enforce minimum length requirements.
Affected products
- Linux Linux Kernel 2.6.39 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-04: disclosed
- 2025-08-28: patched: Patched in various stable branches including 6.12.43 and 6.6.103
References
- https://git.kernel.org/stable/c/09906650484a09b3a4d4b3d3065395856810becd
- https://git.kernel.org/stable/c/0bb32863426afe0badac25c28d59021f211d0f48
- https://git.kernel.org/stable/c/19eb5d8e6aa1169d368a4d69aae5572950deb89d
- https://git.kernel.org/stable/c/529fd5593b721e6f4370c591f5086649ed149ff6
- https://git.kernel.org/stable/c/a0f744d6cdde81d7382e183f77a4080a39b206cd
- https://git.kernel.org/stable/c/bc07cae4f36bb18d5b6a9ed835c1278ca44ec82e
- https://git.kernel.org/stable/c/c33280d6bd668dbdc5a5f07887cc63a52ab4789c