Executive brief
A vulnerability was identified in the Linux kernel's media tuner driver for XC5000 devices. This flaw could allow a local attacker to cause a system crash or potentially execute unauthorized code by triggering a race condition during device disconnection. The issue stems from how the system handles background tasks when the hardware is being released.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/media/tuners/xc5000.c within the xc5000_release function. The driver originally used cancel_delayed_work() to stop the timer_sleep task, which does not guarantee the task has finished execution before the associated private data structure (xc5000_priv) is freed via kfree(). If the delayed work callback (xc5000_do_timer_sleep) runs concurrently with the release thread, it may attempt to dereference the already-freed memory. The fix replaces the asynchronous cancellation with cancel_delayed_work_sync() to ensure the work item is fully terminated before memory deallocation. This issue was resolved in multiple stable kernel branches including 5.4.301, 5.10.246, and various 6.x releases.
Affected products
- Linux Linux Kernel 3.16 to 6.12.y
Timeline
- 2025-09-17: patched: Initial patch submitted by Duoming Zhou
- 2025-10-15: advisory: CVE-2025-39994 published
References
- https://git.kernel.org/stable/c/3f876cd47ed8bca1e28d68435845949f51f90703
- https://git.kernel.org/stable/c/40b7a19f321e65789612ebaca966472055dab48c
- https://git.kernel.org/stable/c/4266f012806fc18e46da4a04d130df59a4946f93
- https://git.kernel.org/stable/c/71ed8b81a4906cb785966910f39cf7f5ad60a69e
- https://git.kernel.org/stable/c/9a00de20ed8ba90888479749b87bc1532cded4ce
- https://git.kernel.org/stable/c/bc4ffd962ce16a154c44c68853b9d93f5b6fc4b8
- https://git.kernel.org/stable/c/df0303b4839520b84d9367c2fad65b13650a4d42