Junglewise Threat Intelligence

CVE-2025-39994: Linux Kernel use-after-free in xc5000 tuner driver release

CVE-2025-39994 · Severity: high · CVSS 7.3 · Published 2025-10-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's media tuner driver for XC5000 devices. This flaw could allow a local attacker to cause a system crash or potentially execute unauthorized code by triggering a race condition during device disconnection. The issue stems from how the system handles background tasks when the hardware is being released.

Technical details

A use-after-free (UAF) vulnerability exists in drivers/media/tuners/xc5000.c within the xc5000_release function. The driver originally used cancel_delayed_work() to stop the timer_sleep task, which does not guarantee the task has finished execution before the associated private data structure (xc5000_priv) is freed via kfree(). If the delayed work callback (xc5000_do_timer_sleep) runs concurrently with the release thread, it may attempt to dereference the already-freed memory. The fix replaces the asynchronous cancellation with cancel_delayed_work_sync() to ensure the work item is fully terminated before memory deallocation. This issue was resolved in multiple stable kernel branches including 5.4.301, 5.10.246, and various 6.x releases.

Affected products

  • Linux Linux Kernel 3.16 to 6.12.y

Timeline

  • 2025-09-17: patched: Initial patch submitted by Duoming Zhou
  • 2025-10-15: advisory: CVE-2025-39994 published

References

Related threats