Executive brief
A vulnerability in the Linux kernel's RainShadow HDMI CEC driver could allow a local attacker to cause a system crash or instability. The issue stems from a race condition in how the driver handles hardware interrupts, which can lead to a buffer overflow. This affects systems using specific USB-based HDMI control hardware.
Technical details
A TOCTOU race condition exists in the rain_interrupt() handler of the rainshadow-cec driver. The driver performs a buffer length check (rain->buf_len) before acquiring the spinlock (rain->buf_lock). Because the buffer length can be concurrently modified by the work handler rain_irq_work_handler(), multiple interrupt invocations can bypass the capacity check. This results in the driver writing data beyond the DATA_SIZE limit, causing a kernel buffer overflow. An attacker with local access could exploit this race condition to cause a kernel panic (Denial of Service). The fix moves the spinlock acquisition to before the length check to ensure atomicity.
Affected products
- Linux Linux Kernel 4.12 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-06-06: patched: Initial patch authored
- 2025-09-05: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1c2769dc80255824542ea5a4ff1a07dcdeb1603f
- https://git.kernel.org/stable/c/2964dbe631fd21ad7873b1752b895548d3c12496
- https://git.kernel.org/stable/c/3c3e33b7edca7a2d6a96801f287f9faeb684d655
- https://git.kernel.org/stable/c/6aaef1a75985865d8c6c5b65fb54152060faba48
- https://git.kernel.org/stable/c/7af160aea26c7dc9e6734d19306128cce156ec40
- https://git.kernel.org/stable/c/ed905fe7cba03cf22ae0b84cf1b73cd1c070423a
- https://git.kernel.org/stable/c/fbc81e78d75bf28972bc22b1599559557b1a1b83