Executive brief
A vulnerability in the Linux kernel's Broadcom VideoCore (bcm_vk) driver could allow a local user to crash the system. The issue occurs when the system attempts to process messages with an insufficient buffer size, leading to a kernel crash (null-pointer dereference). This primarily impacts system availability and could be used to disrupt operations on affected hardware.
Technical details
A NULL pointer dereference vulnerability exists in the bcm_vk_read() function within drivers/misc/bcm-vk/bcm_vk_msg.c. The vulnerability is triggered when a message entry is NULL and the return code is set to -EMSGSIZE; the code subsequently attempts to access members of the NULL 'entry' pointer to populate a temporary message structure for the user. A local attacker with access to the device can exploit this by providing a buffer that is too small for the message, causing a kernel oops and denial of service. The fix involves caching the necessary values from the iterator into temporary variables before the potential NULL assignment occurs.
Affected products
- Linux Linux Kernel 5.19 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2025-12-11: other: Patch submitted by developer
- 2026-03-04: patched: Committed to stable kernel trees
- 2026-05-06: advisory: CVE published
References
- https://git.kernel.org/stable/c/20f2d9dbe5e972516f8f9948d7ae5b95d1ad77bd
- https://git.kernel.org/stable/c/3842f93e6e29d5cc1dcb9e5bda70587b444bed69
- https://git.kernel.org/stable/c/741c5a3a0cd893a4218fc0fc8c18403e54fcfb22
- https://git.kernel.org/stable/c/aa97ccc3dc1eba9f4537f0410e9dbb0b05ccf2fb
- https://git.kernel.org/stable/c/ba75ecb97d3f4e95d59002c13afb6519205be6cb
- https://git.kernel.org/stable/c/ece3722169ba93734bfd1f06255e8ab7f19fe964