Junglewise Threat Intelligence

CVE-2025-39710: Linux Kernel Venus driver out-of-bounds access in hfi_venus

CVE-2025-39710 · Severity: high · CVSS 7.8 · Published 2025-09-05

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's Venus video driver could allow a local attacker to cause a system crash or potentially access sensitive memory. The Venus driver is responsible for hardware-accelerated video encoding and decoding on certain hardware platforms. This issue occurs when the system processes data from the hardware's firmware without properly verifying the size of the incoming data packets.

Technical details

An out-of-bounds (OOB) memory access vulnerability exists in the Linux kernel's Venus HFI (Host Firmware Interface) implementation. The root cause is located in 'drivers/media/platform/qcom/venus/hfi_venus.c' within the 'venus_read_queue' function, where the driver fails to validate that the packet size reported in the header matches the actual number of available words in shared memory. A local attacker with low privileges could potentially exploit this to trigger an OOB read or write, leading to a denial of service (kernel panic) or information disclosure. The vulnerability has been addressed by adding a check to ensure the packet header size matches the expected 'dwords' count after reading from shared memory.

Affected products

  • Linux Linux Kernel 4.13 to 6.14
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-05-19: other: Patch authored
  • 2025-09-05: disclosed: CVE published

References

Related threats