Junglewise Threat Intelligence

CVE-2025-39869: Linux Kernel out-of-bounds write in TI EDMA dmaengine driver

CVE-2025-39869 · Severity: high · CVSS 8.4 · Published 2025-09-23

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory allocation error in the Linux kernel's TI EDMA driver can cause system instability or crashes. This component is responsible for managing direct memory access on certain Texas Instruments hardware platforms, such as those used in industrial or embedded systems. An exploit could lead to a complete system failure or allow an attacker to compromise the integrity of the operating system.

Technical details

A vulnerability exists in the edma_setup_from_hw() function within drivers/dma/ti/edma.c due to an incorrect size calculation during memory allocation for queue_priority_map. The variable is declared as a pointer to an array of two s8 elements (s8 (*)[2]), but the allocation via devm_kcalloc() incorrectly used sizeof(s8) instead of the full array size. This results in a heap-based buffer overflow when the driver attempts to initialize the map, leading to out-of-bounds writes. On ARM platforms like the BeagleBoard-X15, this corruption can trigger 'undefined instruction' faults or kernel hardening features, resulting in a Denial of Service (DoS) or potential privilege escalation. The issue is resolved by using sizeof(*queue_priority_map) to ensure the correct allocation size.

Affected products

  • Linux Linux Kernel 4.4 to 6.1.153, 6.6.x, 6.10.x, 6.11.x

Timeline

  • 2025-08-30: disclosed: Initial patch submitted by Anders Roxell
  • 2025-09-19: patched: Patch committed to stable branches
  • 2025-09-23: advisory: CVE-2025-39869 published

References

Related threats