Junglewise Threat Intelligence

CVE-2025-39709: Linux Kernel Venus driver NULL pointer dereference during probe

CVE-2025-39709 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Siemens SIMATIC CN 4100, Linux Kernel, Linux. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's Venus video driver could allow a local user to crash the system. The issue occurs during the system startup process when the hardware sends a signal before the software is fully ready to handle it. This results in a system crash (NULL pointer dereference), which can impact the availability of devices using specific Qualcomm hardware, such as certain industrial controllers and embedded systems.

Technical details

A race condition exists in the Venus video driver (drivers/media/platform/qcom/venus/core.c) during the probe sequence. The driver was requesting a threaded IRQ via devm_request_threaded_irq() before calling hfi_create(), which initializes the Host Firmware Interface (HFI) structures. If a spurious interrupt occurs between these two calls, the interrupt handler attempts to access uninitialized HFI structures, resulting in a NULL pointer dereference and a kernel oops. This has been observed on Rb3Gen2 hardware during boot. The fix reorders the operations to ensure hfi_create() completes before the IRQ is registered.

Affected products

  • Linux Linux 4.13 to 6.14
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-06-06: patched: Initial patch authored
  • 2025-09-05: disclosed: CVE published

References

Related threats