CVE-2025-39993: media: rc: fix races with imon_disconnect()
In the Linux kernel, the following vulnerability has been resolved:
media: rc: fix races with imon_disconnect()
Syzbot reports a KASAN issue as below:
BUG: KASAN: use-after-free in __create_pipe include/linux/usb.h:1945 [inline]
BUG: KASAN: use-after-free in send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627
Read of size 4 at addr ffff8880256fb000 by task syz-executor314/4465
CPU: 2 PID: 4465 Comm: syz-executor314 Not tainted 6.0.0-rc1-syzkaller #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106
print_address_description mm/kasan/report.c:317 [inline]
print_report.cold+0x2ba/0x6e9 mm/kasan/report.c:433
kasan_report+0xb1/0x1e0 mm/kasan/report.c:495
__create_pipe include/linux/usb.h:1945 [inline]
send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627
vfd_write+0x2d9/0x550 drivers/media/rc/imon.c:991
vfs_write+0x2d7/0xdd0 fs/read_write.c:576
ksys_write+0x127/0x250 fs/read_write.c:631
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd
The iMON driver improperly releases the usb_device reference in
imon_disconnect without coordinating with active users of the
device.
Specifically, the fields usbdev_intf0 and usbdev_intf1 are not
protected by the users counter (ictx->users). During probe,
imon_init_intf0 or imon_init_intf1 increments the usb_device
reference count depending on the interface. However, during
disconnect, usb_put_dev is called unconditionally, regardless of
actual usage.
As a result, if vfd_write or other operations are still in
progress after disconnect, this can lead to a use-after-free of
the usb_device pointer.
Thread 1 vfd_write Thread 2 imon_disconnect
...
if
usb_put_dev(ictx->usbdev_intf0)
else
usb_put_dev(ictx->usbdev_intf1)
...
while
send_packet
if
pipe = usb_sndintpipe(
ictx->usbdev_intf0) UAF
else
pipe = usb_sndctrlpipe(
ictx->usbdev_intf0, 0) UAF
Guard access to usbdev_intf0 and usbdev_intf1 after disconnect by
checking ictx->disconnected in all writer paths. Add early return
with -ENODEV in send_packet(), vfd_write(), lcd_write() and
display_open() if the device is no longer present.
Set and read ictx->disconnected under ictx->lock to ensure memory
synchronization. Acquire the lock in imon_disconnect() before setting
the flag to synchronize with any ongoing operations.
Ensure writers exit early and safely after disconnect before the USB
core proceeds with cleanup.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Security readout for executives and security teams
Plain-English summary
Removing an iMON USB device while it is being used can leave the Linux kernel accessing freed memory. This may cause a crash, data corruption, or possible local compromise. Exposure depends on the affected iMON driver path being available; this is not presented as a remotely reachable flaw.
Executive priority
Prioritize near-term kernel remediation for systems using iMON devices, especially multi-user or otherwise untrusted local environments. Treat other systems as inventory-driven rather than an internet-wide emergency. Confirm vendor backports before declaring systems fixed because the supplied branch data is not sufficient for exact package-level conclusions.
Technical view
A race in the iMON media remote-control driver allows imon_disconnect() to release a usb_device reference while writer operations still use usbdev_intf0 or usbdev_intf1. The resulting use-after-free was observed by KASAN. The fix synchronizes a disconnected flag under ictx->lock and returns -ENODEV from affected writer and open paths.
Likely exposure
Most likely exposure is on Linux systems using, or permitting access to, supported iMON USB hardware and the associated driver. The supplied version data spans several kernel branches but does not clearly map distribution backports. The CVSS vector requires local access with low privileges; internet exposure alone does not establish vulnerability.
Exploitation context
The bundle marks this CVE as absent from KEV and provides no evidence of active exploitation. Discovery came from Syzkaller with KASAN. Exploitation would require locally reaching the iMON driver while device disconnection races an active operation; practical reliability is not established.
Researcher notes
The flaw centers on usb_device lifetime management during imon_disconnect(). Relevant paths include send_packet(), vfd_write(), lcd_write(), and display_open(). The supplied fix checks ictx->disconnected under ictx->lock before USB cleanup continues. The bundle provides no CWE assignment, public exploit evidence, or proof that the CVSS confidentiality and integrity impacts are practically achievable.
Mitigation direction
Update to a vendor-supported kernel containing the applicable upstream stable fix for CVE-2025-39993.
Confirm distribution backport status because kernel package versions may not directly match upstream version labels.
If updating is delayed, request vendor-supported mitigation guidance; the sources name no alternative workaround.
Validation and detection
Inventory installed kernel and distribution package versions across systems using iMON hardware.
Determine whether the iMON driver and compatible USB hardware are present and operational.
Verify the installed kernel includes synchronized disconnected checks in the affected writer and open paths.
Review kernel logs for use-after-free or KASAN reports involving imon.c after device disconnection.
Test normal iMON use and disconnection after updating, monitoring for crashes or sanitizer findings.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-39993 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.