Executive brief
A vulnerability in the Linux kernel's Venus video driver could allow a local user to crash the system. The issue occurs during the system startup process when the hardware sends a signal before the software is fully ready to handle it. This results in a system crash (NULL pointer dereference), which can impact the availability of devices using specific Qualcomm hardware, such as certain industrial controllers and embedded systems.
Technical details
A race condition exists in the Venus video driver (drivers/media/platform/qcom/venus/core.c) during the probe sequence. The driver was requesting a threaded IRQ via devm_request_threaded_irq() before calling hfi_create(), which initializes the Host Firmware Interface (HFI) structures. If a spurious interrupt occurs between these two calls, the interrupt handler attempts to access uninitialized HFI structures, resulting in a NULL pointer dereference and a kernel oops. This has been observed on Rb3Gen2 hardware during boot. The fix reorders the operations to ensure hfi_create() completes before the IRQ is registered.
Affected products
- Linux Linux 4.13 to 6.14
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2025-06-06: patched: Initial patch authored
- 2025-09-05: disclosed: CVE published
References
- https://git.kernel.org/stable/c/18c2b2bd982b8546312c9a7895515672169f28e0
- https://git.kernel.org/stable/c/3200144a2fa4209dc084a19941b9b203b43580f0
- https://git.kernel.org/stable/c/37cc0ac889b018097c217c5929fd6dc2aed636a1
- https://git.kernel.org/stable/c/639eb587f977c02423f4762467055b23902b4131
- https://git.kernel.org/stable/c/88cf63c2599761c48dec8f618d57dccf8f6f4b53
- https://git.kernel.org/stable/c/9db6a78bc5e418e0064e2248c8f3b9b9e8418646
- https://git.kernel.org/stable/c/e796028b4835af00d9a38ebbb208ec3a6634702a