Executive brief
A vulnerability in the Linux kernel's usbtv driver, used for USB video capture devices, could allow a local user to crash the system. By changing video standards (such as from NTSC to PAL) while a video stream is active, the system attempts to write data into a memory buffer that is too small for the new resolution. This results in a kernel crash, impacting system availability and potentially allowing for further unauthorized actions.
Technical details
A buffer overflow exists in the usbtv driver (drivers/media/usb/usbtv/usbtv-video.c) within the Linux kernel. The vulnerability is triggered when a local user changes the TV standard (e.g., NTSC to PAL) via a secondary program while a primary program is actively streaming. This change increases the resolution stored in the usbtv struct without reallocating or adjusting the associated video plane buffer. Subsequent copy operations to the undersized buffer result in writes to unmapped memory, causing a kernel panic. The fix introduces a check using vb2_is_busy() to return -EBUSY if a resolution change is attempted during active streaming.
Affected products
- Linux Linux Kernel 3.14 to 6.13.y
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2025-09-05: advisory: Initial NVD publication
- 2025-08-28: patched: Patched in various stable kernel branches
References
- https://git.kernel.org/stable/c/3d83d0b5ae5045a7a246ed116b5f6c688a12f9e9
- https://git.kernel.org/stable/c/5427dda195d6baf23028196fd55a0c90f66ffa61
- https://git.kernel.org/stable/c/7e40e0bb778907b2441bff68d73c3eb6b6cd319f
- https://git.kernel.org/stable/c/9f886d21e235c4bd038cb20f6696084304197ab3
- https://git.kernel.org/stable/c/c35e7c7a004ef379a1ae7c7486d4829419acad1d
- https://git.kernel.org/stable/c/c3d75524e10021aa5c223d94da4996640aed46c0
- https://git.kernel.org/stable/c/ee7bade8b9244834229b12b6e1e724939bedd484