Junglewise Threat Intelligence

CVE-2025-39790: Linux Kernel double free in MHI host driver

CVE-2025-39790 · Severity: high · CVSS 8.4 · Published 2025-09-11

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's Modem Host Interface (MHI) bus driver could allow a local attacker or a compromised peripheral device to cause a system crash or potentially execute unauthorized code. The issue occurs when the system processes communication events from hardware devices incorrectly, leading to memory corruption. This affects systems using MHI for high-speed communication with modems or other external peripherals, including certain industrial automation components.

Technical details

A double-free vulnerability exists in the Linux kernel's MHI (Modem Host Interface) host driver within 'drivers/bus/mhi/host/main.c'. The root cause is a race condition or lack of validation when the host processes completion events from a remote device; if the device sends an event pointing to an unexpected Transfer Ring Element (TRE) before updating event contents, the host may process stale data. Specifically, if the event pointer is multiple elements ahead of the host's local read pointer and not part of a chained transaction, the host may incorrectly free buffers multiple times via xfer_cb(). This can be triggered by a malicious or malfunctioning endpoint device. Patches have been released across multiple stable kernel branches to ensure events point to expected TREs.

Affected products

  • Linux Linux Kernel 5.7 to 6.15.y
  • Siemens SIMATIC CN 4100 < V5.0

Timeline

  • 2025-07-14: other: Patch authored by Youssef Samir
  • 2025-08-28: patched: Commits merged into stable branches by Greg Kroah-Hartman
  • 2025-09-11: disclosed: CVE published

References

Related threats