Junglewise Threat Intelligence

CVE-2025-39687: Linux Kernel information disclosure in as73211 light sensor driver

CVE-2025-39687 · Severity: high · CVSS 7.1 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's light sensor driver could allow a local user to access sensitive information from the system's memory. The issue occurs because the driver fails to clear internal memory buffers before passing them to user-accessible areas. This could potentially lead to the exposure of data from other processes or the kernel itself.

Technical details

An information disclosure vulnerability exists in the Linux kernel's IIO (Industrial I/O) subsystem, specifically within the as73211 light sensor driver. The 'as73211_trigger_handler' function fails to initialize the 'scan' structure, which contains padding or 'holes' between its members (the channel data and the timestamp). Because this uninitialized structure is copied into a kfifo that is readable by user space, a local attacker can read residual kernel memory contents. The fix involves properly zero-initializing the structure before use. Patches have been backported to multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 5.10 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-08-02: patched: Initial patch authored by Jonathan Cameron
  • 2025-09-05: disclosed: CVE published

References

Related threats