Junglewise Threat Intelligence

CVE-2025-39684: Linux Kernel information leak in Comedi subsystem

CVE-2025-39684 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Comedi subsystem, which handles data acquisition from hardware, could allow a local user to access sensitive information from the system's memory. This occurs because certain hardware instructions do not properly clear internal memory buffers before sending data back to the user. An attacker could exploit this to read data they are not authorized to see, potentially compromising system security or user privacy.

Technical details

A kernel information leak vulnerability exists in the Linux kernel Comedi driver (drivers/comedi/comedi_fops.c). The issue stems from the do_insn_ioctl() and do_insnlist_ioctl() functions failing to initialize kernel buffers before they are partially filled by instruction handlers and subsequently copied back to user-space. Specifically, handlers like insn_rw_emulate_bits() and vm80xx_ai_insn_read() may not fill the entire allocated buffer, leaving residual kernel data in the remaining bytes. A local attacker can exploit this to read uninitialized kernel memory. The fix involves zeroing the allocated buffer before instruction handling to ensure no sensitive data is leaked. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 2.6.29 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-07-25: patched: Initial patch authored by Ian Abbott
  • 2025-09-05: disclosed: CVE-2025-39684 published

References

Related threats