Executive brief
A vulnerability in the Linux kernel's support for Bosch Sensortec BNO055 IMU sensors could allow a local user to cause a system crash or potentially access sensitive memory. This component is typically used in devices that require motion sensing, such as robotics or mobile hardware. While the risk of a successful exploit is considered low due to specific internal code logic, it represents a flaw in how the system handles sensor data translation.
Technical details
An out-of-bounds (OOB) read vulnerability exists in drivers/iio/imu/bno055/bno055.c within the bno055_get_regmask() function. The root cause is an incorrect loop iteration where the hw_xlate array was being iterated over using the length of the vals array. In specific configurations like bno055_gyr_scale, the vals array is larger than the hw_xlate array, leading to a potential OOB access. Although the risk is mitigated by the fact that a match is typically found before the boundary is crossed, a crafted or unexpected hardware state could trigger the read beyond the array bounds. The fix introduces a dedicated hw_xlate_len field to ensure correct iteration bounds.
Affected products
- Linux Linux Kernel 6.1 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-09-05: advisory: Initial disclosure of CVE-2025-39719
- 2025-08-28: patched: Patches applied to various stable kernel branches
References
- https://git.kernel.org/stable/c/399b883ec828e436f1a721bf8551b4da8727e65b
- https://git.kernel.org/stable/c/4808ca3aa30ae857454d0b41d2d0bf161a312b45
- https://git.kernel.org/stable/c/50e823a23816b792daf6e8405f8d6045952bb90e
- https://git.kernel.org/stable/c/5c2b601922c064f7be70ae8621277f18d1ffec59
- https://git.kernel.org/stable/c/a0691ab6334f1769acc64ea9e319414a682ff45d
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html