Junglewise Threat Intelligence

CVE-2025-39809: Linux Kernel stack out-of-bounds write in Intel THC QuickI2C driver

CVE-2025-39809 · Severity: high · CVSS 8.4 · Published 2025-09-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Intel Touch Host Controller (THC) driver could allow a local attacker to cause a system crash or potentially gain unauthorized access to sensitive information. The issue occurs when the system processes specific hardware configuration data, leading to a memory error. This could impact the stability and security of devices using Intel QuickI2C interfaces.

Technical details

A stack-based out-of-bounds write (CWE-787) exists in the intel-quicki2c driver within the Intel THC HID subsystem. The vulnerability is caused by the ACPI _DSD methods returning ICRS and ISUB data with a trailing byte that exceeds the defined size of the internal structures `quicki2c_subip_acpi_parameter` and `quicki2c_subip_acpi_config`. When `quicki2c_acpi_get_dsd_property` performs a memory copy, it writes past the end of the stack-allocated buffer. This can be triggered during ACPI resource enumeration, leading to a kernel panic (KASAN detected stack-out-of-bounds). The fix involves adding reserved padding bytes to the affected structures to accommodate the extra data.

Affected products

  • Linux Linux Kernel 6.14 to 6.16.5

Timeline

  • 2025-08-03: patched: Initial patch authored
  • 2025-09-16: disclosed: CVE published

References

Related threats