Junglewise Threat Intelligence

CVE-2025-38694: Linux Kernel NULL pointer dereference in dib7090p DVB driver

CVE-2025-38694 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's digital video broadcasting (DVB) driver could allow a local user to crash the system. The issue exists in the DiB7090P frontend driver, which is used to manage certain television tuner hardware. An attacker with local access could trigger a system failure (kernel crash), leading to a denial of service.

Technical details

A NULL pointer dereference vulnerability exists in the dib7090p_rw_on_apb() function within drivers/media/dvb-frontends/dib7000p.c. The root cause is a lack of sanity checking on user-controlled I2C message lengths (msg[0].len and msg[1].len). When a user provides a message with a length of zero or insufficient size, the driver attempts to access buffer offsets (e.g., msg[0].buf[2]) without verifying the buffer is valid or large enough, leading to a kernel oops. This can be exploited by a local attacker with permissions to interact with the media subsystem to cause a denial of service. Patches have been released across multiple stable kernel branches to enforce minimum length requirements.

Affected products

  • Linux Linux Kernel 2.6.39 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-09-04: disclosed
  • 2025-08-28: patched: Patched in various stable branches including 6.12.43 and 6.6.103

References

Related threats