Junglewise Threat Intelligence

CVE-2025-39680: Linux Kernel out-of-bounds bug in rtl9300_i2c_smbus_xfer

CVE-2025-39680 · Severity: high · CVSS 7.8 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's I2C driver for Realtek RTL9300 chips, which are commonly used in networking hardware. A local user could provide a specially crafted input that causes the system to access memory outside of intended boundaries. This could lead to a system crash, data exposure, or potentially allow an attacker to gain elevated control over the device.

Technical details

An out-of-bounds (OOB) read/write vulnerability exists in the rtl9300_i2c_smbus_xfer function within drivers/i2c/busses/i2c-rtl9300.c. The root cause is a failure to validate the 'data->block[0]' variable, which is provided by the user, before using it to configure I2C transfers. An attacker with local access can provide a value exceeding I2C_SMBUS_BLOCK_MAX, leading to memory corruption or information disclosure. The issue has been resolved by adding a check to ensure the block length is between 1 and I2C_SMBUS_BLOCK_MAX. The fix is available in kernel versions 6.16.4 and later.

Affected products

  • Linux Linux Kernel 6.13 to 6.16.3

Timeline

  • 2025-08-10: patched: Initial patch authored by Alex Guo
  • 2025-09-05: disclosed: CVE-2025-39680 published

References

Related threats