CVE-2025-39714 (GCVE-0-2025-39714)
Vulnerability from cvelistv5
Published
2025-09-05 17:21
Modified
2026-08-05 12:04
Summary
In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Lock resolution while streaming When an program is streaming (ffplay) and another program (qv4l2) changes the TV standard from NTSC to PAL, the kernel crashes due to trying to copy to unmapped memory. Changing from NTSC to PAL increases the resolution in the usbtv struct, but the video plane buffer isn't adjusted, so it overflows. [hverkuil: call vb2_is_busy instead of vb2_is_streaming]
Impacted products
Vendor Product Version
Linux Linux Version: 0e0fe3958fdd13dbf55c3a787acafde6efd04272
Version: 0e0fe3958fdd13dbf55c3a787acafde6efd04272
Version: 0e0fe3958fdd13dbf55c3a787acafde6efd04272
Version: 0e0fe3958fdd13dbf55c3a787acafde6efd04272
Version: 0e0fe3958fdd13dbf55c3a787acafde6efd04272
Version: 0e0fe3958fdd13dbf55c3a787acafde6efd04272
Version: 0e0fe3958fdd13dbf55c3a787acafde6efd04272
Version: 0e0fe3958fdd13dbf55c3a787acafde6efd04272
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T17:42:41.101Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC CN 4100",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V5.0",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-12T12:06:31.361Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/media/usb/usbtv/usbtv-video.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "c35e7c7a004ef379a1ae7c7486d4829419acad1d",
              "status": "affected",
              "version": "0e0fe3958fdd13dbf55c3a787acafde6efd04272",
              "versionType": "git"
            },
            {
              "lessThan": "ee7bade8b9244834229b12b6e1e724939bedd484",
              "status": "affected",
              "version": "0e0fe3958fdd13dbf55c3a787acafde6efd04272",
              "versionType": "git"
            },
            {
              "lessThan": "5427dda195d6baf23028196fd55a0c90f66ffa61",
              "status": "affected",
              "version": "0e0fe3958fdd13dbf55c3a787acafde6efd04272",
              "versionType": "git"
            },
            {
              "lessThan": "ef9b3c22405192afaa279077ddd45a51db90b83d",
              "status": "affected",
              "version": "0e0fe3958fdd13dbf55c3a787acafde6efd04272",
              "versionType": "git"
            },
            {
              "lessThan": "3d83d0b5ae5045a7a246ed116b5f6c688a12f9e9",
              "status": "affected",
              "version": "0e0fe3958fdd13dbf55c3a787acafde6efd04272",
              "versionType": "git"
            },
            {
              "lessThan": "c3d75524e10021aa5c223d94da4996640aed46c0",
              "status": "affected",
              "version": "0e0fe3958fdd13dbf55c3a787acafde6efd04272",
              "versionType": "git"
            },
            {
              "lessThan": "9f886d21e235c4bd038cb20f6696084304197ab3",
              "status": "affected",
              "version": "0e0fe3958fdd13dbf55c3a787acafde6efd04272",
              "versionType": "git"
            },
            {
              "lessThan": "7e40e0bb778907b2441bff68d73c3eb6b6cd319f",
              "status": "affected",
              "version": "0e0fe3958fdd13dbf55c3a787acafde6efd04272",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/media/usb/usbtv/usbtv-video.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.14"
            },
            {
              "lessThan": "3.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.297",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.241",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.190",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.149",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.103",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.44",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.16.*",
              "status": "unaffected",
              "version": "6.16.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.17",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.297",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.241",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.190",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.149",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.103",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.44",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16.4",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: usbtv: Lock resolution while streaming\n\nWhen an program is streaming (ffplay) and another program (qv4l2)\nchanges the TV standard from NTSC to PAL, the kernel crashes due to trying\nto copy to unmapped memory.\n\nChanging from NTSC to PAL increases the resolution in the usbtv struct,\nbut the video plane buffer isn\u0027t adjusted, so it overflows.\n\n[hverkuil: call vb2_is_busy instead of vb2_is_streaming]"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Exploitation is entirely through local ioctls (VIDIOC_REQBUFS, VIDIOC_S_STD, VIDIOC_STREAMON) on the /dev/videoN character device node exposed by the usbtv driver; the attacker needs no physical access, only a local account on a system where a USBTV007 capture device is attached (video ingest appliances, kiosks, digitization/surveillance stations).\nAC:L - The attacker controls every step and no race is needed \u2014 buffers are sized once at REQBUFS and queue_setup is never re-run at STREAMON, so a single-threaded sequence of REQBUFS (default NTSC 720x480) then S_STD(PAL/SECAM 720x576) then STREAMON deterministically makes n_chunks exceed the allocated plane size, and the v4l2 core imposes no streaming/busy gate on S_STD.\nPR:L - Only an open file descriptor on the V4L2 device node is needed; v4l_s_std() and video_ioctl2() enforce no capability check, and the node is reachable by any unprivileged user in the video group or the console user via systemd-logind uaccess ACLs.\nUI:N - A single attacker-controlled process performs the allocation, standard change and stream start itself; the two-program scenario in the commit message (ffplay plus qv4l2) is merely how it was observed, not a requirement.\nS:U - The out-of-bounds write corrupts kernel memory within the same kernel security authority, with no crossing of a VM, IOMMU or sandbox boundary.\nC:H - The ~138 KB out-of-bounds write into vmalloc space can corrupt adjacent allocations \u2014 other vb2 planes, VMAP_STACK kernel stacks, BPF JIT pages, module data \u2014 and such corruption of neighboring pointers, length fields and control flow is leverageable into arbitrary kernel memory disclosure.\nI:H - This is an out-of-bounds heap write of up to ~138 KB past the vmalloc_user() plane, with the written bytes taken from the ISO video payload that an attacker controlling the analog input or emulating the USBTV007 device can fully choose, yielding a control-flow hijack primitive against adjacent vmalloc objects.\nA:H - The write reliably hits the vmalloc guard page and faults on unmapped memory inside the ISO URB completion handler under spin_lock_irqsave, producing the kernel oops/panic explicitly reported in the fix commit."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:04:47.367Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c35e7c7a004ef379a1ae7c7486d4829419acad1d"
        },
        {
          "url": "https://git.kernel.org/stable/c/ee7bade8b9244834229b12b6e1e724939bedd484"
        },
        {
          "url": "https://git.kernel.org/stable/c/5427dda195d6baf23028196fd55a0c90f66ffa61"
        },
        {
          "url": "https://git.kernel.org/stable/c/ef9b3c22405192afaa279077ddd45a51db90b83d"
        },
        {
          "url": "https://git.kernel.org/stable/c/3d83d0b5ae5045a7a246ed116b5f6c688a12f9e9"
        },
        {
          "url": "https://git.kernel.org/stable/c/c3d75524e10021aa5c223d94da4996640aed46c0"
        },
        {
          "url": "https://git.kernel.org/stable/c/9f886d21e235c4bd038cb20f6696084304197ab3"
        },
        {
          "url": "https://git.kernel.org/stable/c/7e40e0bb778907b2441bff68d73c3eb6b6cd319f"
        }
      ],
      "title": "media: usbtv: Lock resolution while streaming",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-39714",
    "datePublished": "2025-09-05T17:21:21.435Z",
    "dateReserved": "2025-04-16T07:20:57.117Z",
    "dateUpdated": "2026-08-05T12:04:47.367Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…