Junglewise Threat Intelligence

CVE-2025-39993: Linux Kernel iMON driver use-after-free in imon_disconnect

CVE-2025-39993 · Severity: high · CVSS 7.8 · Published 2025-10-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's iMON driver, which manages certain infrared remote control and display devices. When one of these devices is unplugged while the system is still trying to send data to it, the system may attempt to access memory that has already been freed. This can lead to a system crash or potentially allow a local user to gain unauthorized control over the system.

Technical details

A use-after-free (UAF) vulnerability exists in drivers/media/rc/imon.c due to improper synchronization between imon_disconnect() and active writer paths like vfd_write() and lcd_write(). The driver unconditionally releases the usb_device reference count via usb_put_dev() during disconnection without checking if other threads are still accessing the device context. A local attacker can trigger this race condition by disconnecting the device while a write operation is in progress, leading to a KASAN-detected UAF in send_packet() or __create_pipe(). The fix involves implementing proper locking and checking a 'disconnected' flag in all writer paths to ensure early exit before the USB core performs cleanup.

Affected products

  • Linux Linux Kernel 21677cfc562a to 9348976003e3, 21677cfc562a to b03fac6e2a38, 21677cfc562a to 71c52b073922, 21677cfc562a to 71096a6161a2, 21677cfc562a to 71da40648741

Timeline

  • 2025-07-29: other: Patch authored
  • 2025-10-15: advisory: NVD publication date

References

Related threats