LiveActive security incident?Get immediate response
CVE Record

CVE-2025-39993: media: rc: fix races with imon_disconnect()

In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot reports a KASAN issue as below: BUG: KASAN: use-after-free in __create_pipe include/linux/usb.h:1945 [inline] BUG: KASAN: use-after-free in send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627 Read of size 4 at addr ffff8880256fb000 by task syz-executor314/4465 CPU: 2 PID: 4465 Comm: syz-executor314 Not tainted 6.0.0-rc1-syzkaller #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106 print_address_description mm/kasan/report.c:317 [inline] print_report.cold+0x2ba/0x6e9 mm/kasan/report.c:433 kasan_report+0xb1/0x1e0 mm/kasan/report.c:495 __create_pipe include/linux/usb.h:1945 [inline] send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627 vfd_write+0x2d9/0x550 drivers/media/rc/imon.c:991 vfs_write+0x2d7/0xdd0 fs/read_write.c:576 ksys_write+0x127/0x250 fs/read_write.c:631 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd The iMON driver improperly releases the usb_device reference in imon_disconnect without coordinating with active users of the device. Specifically, the fields usbdev_intf0 and usbdev_intf1 are not protected by the users counter (ictx->users). During probe, imon_init_intf0 or imon_init_intf1 increments the usb_device reference count depending on the interface. However, during disconnect, usb_put_dev is called unconditionally, regardless of actual usage. As a result, if vfd_write or other operations are still in progress after disconnect, this can lead to a use-after-free of the usb_device pointer. Thread 1 vfd_write Thread 2 imon_disconnect ... if usb_put_dev(ictx->usbdev_intf0) else usb_put_dev(ictx->usbdev_intf1) ... while send_packet if pipe = usb_sndintpipe( ictx->usbdev_intf0) UAF else pipe = usb_sndctrlpipe( ictx->usbdev_intf0, 0) UAF Guard access to usbdev_intf0 and usbdev_intf1 after disconnect by checking ictx->disconnected in all writer paths. Add early return with -ENODEV in send_packet(), vfd_write(), lcd_write() and display_open() if the device is no longer present. Set and read ictx->disconnected under ictx->lock to ensure memory synchronization. Acquire the lock in imon_disconnect() before setting the flag to synchronize with any ongoing operations. Ensure writers exit early and safely after disconnect before the USB core proceeds with cleanup. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Removing an iMON USB device while it is being used can leave the Linux kernel accessing freed memory. This may cause a crash, data corruption, or possible local compromise. Exposure depends on the affected iMON driver path being available; this is not presented as a remotely reachable flaw.

Executive priority

Prioritize near-term kernel remediation for systems using iMON devices, especially multi-user or otherwise untrusted local environments. Treat other systems as inventory-driven rather than an internet-wide emergency. Confirm vendor backports before declaring systems fixed because the supplied branch data is not sufficient for exact package-level conclusions.

Technical view

A race in the iMON media remote-control driver allows imon_disconnect() to release a usb_device reference while writer operations still use usbdev_intf0 or usbdev_intf1. The resulting use-after-free was observed by KASAN. The fix synchronizes a disconnected flag under ictx->lock and returns -ENODEV from affected writer and open paths.

Likely exposure

Most likely exposure is on Linux systems using, or permitting access to, supported iMON USB hardware and the associated driver. The supplied version data spans several kernel branches but does not clearly map distribution backports. The CVSS vector requires local access with low privileges; internet exposure alone does not establish vulnerability.

Exploitation context

The bundle marks this CVE as absent from KEV and provides no evidence of active exploitation. Discovery came from Syzkaller with KASAN. Exploitation would require locally reaching the iMON driver while device disconnection races an active operation; practical reliability is not established.

Researcher notes

The flaw centers on usb_device lifetime management during imon_disconnect(). Relevant paths include send_packet(), vfd_write(), lcd_write(), and display_open(). The supplied fix checks ictx->disconnected under ictx->lock before USB cleanup continues. The bundle provides no CWE assignment, public exploit evidence, or proof that the CVSS confidentiality and integrity impacts are practically achievable.

Mitigation direction

  • Update to a vendor-supported kernel containing the applicable upstream stable fix for CVE-2025-39993.
  • Confirm distribution backport status because kernel package versions may not directly match upstream version labels.
  • If updating is delayed, request vendor-supported mitigation guidance; the sources name no alternative workaround.

Validation and detection

  • Inventory installed kernel and distribution package versions across systems using iMON hardware.
  • Determine whether the iMON driver and compatible USB hardware are present and operational.
  • Verify the installed kernel includes synchronized disconnected checks in the affected writer and open paths.
  • Review kernel logs for use-after-free or KASAN reports involving imon.c after device disconnection.
  • Test normal iMON use and disconnection after updating, monitoring for crashes or sanitizer findings.
Prepared
Confidence
medium
Sources
11

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-39993 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
10Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2025-39993Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux21677cfc562a27e099719d413287bc8d1d24deb7, 21677cfc562a27e099719d413287bc8d1d24deb7, 21677cfc562a27e099719d413287bc8d1d24deb7, 21677cfc562a27e099719d413287bc8d1d24deb7, 21677cfc562a27e099719d413287bc8d1d24deb7, 21677cfc562a27e099719d413287bc8d1d24deb7, 21677cfc562a27e099719d413287bc8d1d24deb7, 21677cfc562a27e099719d413287bc8d1d24deb7, 21677cfc562a27e099719d413287bc8d1d24deb7unaffected
LinuxLinux2.6.35, 0, 5.4.301, 5.10.246, 5.15.195, 6.1.156, 6.6.110, 6.12.51, 6.16.11, 6.17.1, 6.18affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.