Junglewise Threat Intelligence

CVE-2025-39806: Linux Kernel slab out-of-bounds access in HID multitouch driver

CVE-2025-39806 · Severity: high · CVSS 8.8 · Published 2025-09-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's multitouch driver, which handles input from devices like touchscreens and touchpads. A malicious or faulty hardware device connected to the system can provide a specially crafted data structure that causes the system to crash or potentially allow unauthorized access to memory. This could lead to a complete system failure or a compromise of sensitive information handled by the operating system.

Technical details

A slab out-of-bounds access vulnerability exists in the mt_report_fixup() function within drivers/hid/hid-multitouch.c. The issue arises when the driver attempts to patch a report descriptor for Goodix GT7868Q devices at byte offset 607 without first verifying that the descriptor is at least 608 bytes long. A malicious HID device providing a smaller descriptor triggers an out-of-bounds read/write. This can be exploited by an attacker with physical access or via an adjacent network (in cases of network-attached HID) to cause a kernel panic (DoS) or potentially achieve local privilege escalation. The vulnerability has been patched in multiple stable branches by adding a mandatory size check before accessing the descriptor buffer.

Affected products

  • Linux Linux Kernel 4.19.y, 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.10.y, 6.11.y

Timeline

  • 2025-08-10: disclosed: Initial patch submitted by Qasim Ijaz
  • 2025-09-04: patched: Patches merged into stable kernel branches
  • 2025-09-16: advisory: CVE-2025-39806 published

References

Related threats