Skip to main content
EPSS 0.1%top 96%

In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot reports a KASAN issue as… (CVE-2025-39993)

0
Medium
Published: 10/15/2025 (10/15/2025, 08:15:00 UTC)
Source: GCVE Database
Product: linux

Description

In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot reports a KASAN issue as below: BUG: KASAN: use-after-free in __create_pipe include/linux/usb.h:1945 [inline] BUG: KASAN: use-after-free in send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627 Read of size 4 at addr ffff8880256fb000 by task syz-executor314/4465 CPU: 2 PID: 4465 Comm: syz-executor314 Not tainted 6.0.0-rc1-syzkaller #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106 print_address_description mm/kasan/report.c:317 [inline] print_report.cold+0x2ba/0x6e9 mm/kasan/report.c:433 kasan_report+0xb1/0x1e0 mm/kasan/report.c:495 __create_pipe include/linux/usb.h:1945 [inline] send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627 vfd_write+0x2d9/0x550 drivers/media/rc/imon.c:991 vfs_write+0x2d7/0xdd0 fs/read_write.c:576 ksys_write+0x127/0x250 fs/read_write.c:631 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd The iMON driver improperly releases the usb_device reference in imon_disconnect without coordinating with active users of the device. Specifically, the fields usbdev_intf0 and usbdev_intf1 are not protected by the users counter (ictx->users). During probe, imon_init_intf0 or imon_init_intf1 increments the usb_device reference count depending on the interface. However, during disconnect, usb_put_dev is called unconditionally, regardless of actual usage. As a result, if vfd_write or other operations are still in progress after disconnect, this can lead to a use-after-free of the usb_device pointer. Thread 1 vfd_write Thread 2 imon_disconnect ... if usb_put_dev(ictx->usbdev_intf0) else usb_put_dev(ictx->usbdev_intf1) ... while send_packet if pipe = usb_sndintpipe( ictx->usbdev_intf0) UAF else pipe = usb_sndctrlpipe( ictx->usbdev_intf0, 0) UAF Guard access to usbdev_intf0 and usbdev_intf1 after disconnect by checking ictx->disconnected in all writer paths. Add early return with -ENODEV in send_packet(), vfd_write(), lcd_write() and display_open() if the device is no longer present. Set and read ictx->disconnected under ictx->lock to ensure memory synchronization. Acquire the lock in imon_disconnect() before setting the flag to synchronize with any ongoing operations. Ensure writers exit early and safely after disconnect before the USB core proceeds with cleanup. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux NFV (v. 8)Red Hat Enterprise Linux RT (v. 8)src<4.4.0-1151.157<4.15.0-1196.211~14.04.1<4.4.0-277.311~14.04.1<4.4.0-277.311<4.4.0-1189.204

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/25/2026, 22:03:44 UTC

Technical Analysis

This advisory covers three security fixes in the Red Hat kernel-rt packages: CVE-2025-39993 addresses race conditions in the media rc subsystem related to imon_disconnect(); CVE-2025-40240 fixes a NULL pointer dereference in SCTP when chunk data buffers are missing; and CVE-2025-68285 resolves a potential use-after-free vulnerability in the libceph function have_mon_and_osd_map(). These vulnerabilities affect the Real Time Linux Kernel used in Red Hat Enterprise Linux 8 variants. The update is rated as important and requires a reboot after installation. No CVSS scores are provided in the advisory, but the severity is assessed as high based on the nature of the flaws and Red Hat's rating.

Potential Impact

Successful exploitation of these vulnerabilities could lead to system instability or crashes due to race conditions, NULL pointer dereferences, or use-after-free bugs in kernel components. This may affect system reliability and could potentially be leveraged for denial of service or other impacts depending on the environment. The advisory does not report known exploits in the wild.

Mitigation Recommendations

Red Hat has released an official security update for the kernel-rt packages addressing these vulnerabilities. Users should apply the update as described in the Red Hat advisory RHSA-2026:0443 and reboot the system to ensure the fixes take effect. No additional mitigations are specified or required beyond applying the official patch.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:0443
Cve Count
3
Additional Cves
["CVE-2025-40240","CVE-2025-68285"]

Threat ID: 6a3da1cb4853345fc18229f6

Added to database: 06/25/2026, 21:46:51 UTC

Last enriched: 06/25/2026, 22:03:44 UTC

Last updated: 09/10/2026, 19:36:50 UTC

Views: 56

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses