Junglewise Threat Intelligence

CVE-2025-39786: Linux Kernel out-of-bounds access in AD7173 ADC driver

CVE-2025-39786 · Severity: high · CVSS 7.8 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Analog-to-Digital Converter (ADC) driver for AD7173 devices could allow a local user to cause a system crash or potentially access sensitive kernel memory. The issue stems from how the system handles internal calibration settings, where an incorrect index could lead to memory errors. This affects systems using specific industrial sensor hardware and could impact operational stability or data confidentiality.

Technical details

An out-of-bounds (OOB) access vulnerability exists in the Linux kernel's IIO ADC driver for the AD7173 (drivers/iio/adc/ad7173.c). The root cause is the use of the 'channel' field instead of the 'address' field when indexing the ad7173_channels array within the syscalib_mode attribute handlers (ad7173_set_syscalib_mode, ad7173_get_syscalib_mode, and ad7173_write_syscalib). Because the 'channel' field is derived from device tree configurations and may not correspond to the 0-based array index, a local attacker with access to the sysfs attributes can trigger an OOB read or write. This can result in a kernel crash (DoS) or potential privilege escalation. The issue has been patched in stable releases including 6.16.4.

Affected products

  • Linux Linux Kernel 6.14 to 6.16.4

Timeline

  • 2025-09-11: disclosed
  • 2025-08-28: patched

References

Related threats