Junglewise Threat Intelligence

CVE-2025-39713: Linux Kernel buffer overflow in RainShadow HDMI CEC driver

CVE-2025-39713 · Severity: medium · CVSS 4.7 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's RainShadow HDMI CEC driver could allow a local attacker to cause a system crash or instability. The issue stems from a race condition in how the driver handles hardware interrupts, which can lead to a buffer overflow. This affects systems using specific USB-based HDMI control hardware.

Technical details

A TOCTOU race condition exists in the rain_interrupt() handler of the rainshadow-cec driver. The driver performs a buffer length check (rain->buf_len) before acquiring the spinlock (rain->buf_lock). Because the buffer length can be concurrently modified by the work handler rain_irq_work_handler(), multiple interrupt invocations can bypass the capacity check. This results in the driver writing data beyond the DATA_SIZE limit, causing a kernel buffer overflow. An attacker with local access could exploit this race condition to cause a kernel panic (Denial of Service). The fix moves the spinlock acquisition to before the length check to ensure atomicity.

Affected products

  • Linux Linux Kernel 4.12 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-06-06: patched: Initial patch authored
  • 2025-09-05: disclosed: CVE published

References

Related threats