Junglewise Threat Intelligence

CVE-2025-39686: Linux Kernel information leak in Comedi insn_rw_emulate_bits

CVE-2025-39686 · Severity: high · CVSS 7.8 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Comedi subsystem, which is used for data acquisition and control. A flaw in how the system handles certain read and write instructions could allow a local attacker to access sensitive information from the kernel's memory or potentially cause system instability. This could lead to the exposure of private data or a disruption of operations on affected systems.

Technical details

A vulnerability exists in the Linux kernel's Comedi driver subsystem within the `insn_rw_emulate_bits()` function. This function emulates `INSN_READ` and `INSN_WRITE` instructions using `INSN_BITS`, but it previously only processed a single sample even when multiple samples (`insn->n`) were requested. Because the Comedi core expects to copy `insn->n` samples back to user-space, this discrepancy resulted in KASAN-detected kernel information leaks when `insn->n` was greater than 1. A local attacker with access to Comedi subdevices could exploit this to read uninitialized kernel memory. The issue has been resolved by updating the emulation function to iterate through all requested samples or return an error.

Affected products

  • Linux Linux Kernel 2.6.29 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-07-25: patched: Initial patch authored by Ian Abbott
  • 2025-09-05: disclosed: CVE published by NVD
  • 2025-10-01: advisory: Debian LTS advisory published

References

Related threats