Junglewise Threat Intelligence

CVE-2025-68819: Linux Kernel out-of-bounds write in dtv5100_i2c_msg

CVE-2025-68819 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's DTV5100 USB TV tuner driver could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs because the driver does not properly validate the size of data received during certain hardware communications. This could lead to memory corruption, impacting the stability and security of systems using this specific hardware driver.

Technical details

An out-of-bounds write vulnerability exists in the dtv5100_i2c_msg() function within the drivers/media/usb/dvb-usb/dtv5100.c component of the Linux kernel. The root cause is a lack of bounds checking on the 'rlen' parameter, which is user-controlled; if 'rlen' exceeds the size of the destination buffer (st->data), a memcpy operation results in a heap-based buffer overflow. A local attacker with sufficient privileges to interact with the device driver can exploit this to cause a denial of service (system crash) or potentially achieve privilege escalation. The vulnerability has been addressed by adding proper range checking to ensure 'rlen' does not exceed the buffer size. Patches are available in various stable kernel branches including 5.10.248, 5.15.198, 6.1.160, 6.6.120, and 6.12.64.

Affected products

  • Linux Linux 2.6.28 to 6.12.64

Timeline

  • 2025-04-21: other: Vulnerability fixed in source code
  • 2026-01-13: disclosed: CVE published

References