Review reviewHigh

CVE-2025-39993

Linux

In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot reports a KASAN issue as below: BUG: KASAN: use-after-free in __create_pipe include/linux/usb.h:1945 [inline] BUG: KASAN: use-after-free in send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627 Read of size 4 at addr ffff8880256fb000 by task syz-executor314/4465 CPU: 2 PID: 4465 Comm: syz-executor314 Not tainted 6.0.0-rc1-syzkaller #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_...

CVSS
7.8
EPSS
0.15%
4.37% percentile
CISA KEV
Not listed
Published
2025.10.15
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.15%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot reports a KASAN issue as below: BUG: KASAN: use-after-free in __create_pipe include/linux/usb.h:1945 [inline] BUG: KASAN: use-after-free in send_packet+0xa2d/0xbc0 drivers/media/rc/imon.c:627 Read of size 4 at addr ffff8880256fb000 by task syz-executor314/4465 CPU: 2 PID: 4465 Comm: syz-executor314 Not tainted 6.0.0-rc1-syzkaller #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_...

Affected product and versions

Product
Linux
Affected versions
>= 21677cfc562a27e099719d413287bc8d1d24deb7 < 9348976003e39754af344949579e824a0a210fc4, >= 21677cfc562a27e099719d413287bc8d1d24deb7 < b03fac6e2a38331faf8510b480becfa90cea1c9f, >= 21677cfc562a27e099719d413287bc8d1d24deb7 < 71c52b073922d05e79e6de7fc7f5f38f927929a4, >= 21677cfc562a27e099719d413287bc8d1d24deb7 < 71096a6161a25e84acddb89a9d77f138502d26ab, >= 21677cfc562a27e099719d413287bc8d1d24deb7 < 71da40648741d15b302700b68973fe8b382aef3c, >= 21677cfc562a27e099719d413287bc8d1d24deb7 < fd5d3e6b149ec8cce045d86a2b5e3664d6b32ba5, >= 21677cfc562a27e099719d413287bc8d1d24deb7 < d9f6ce99624a41c3bcb29a8d7d79b800665229dd, >= 21677cfc562a27e099719d413287bc8d1d24deb7 < 2e7fd93b9cc565b839bc55a6662475718963e156, >= 21677cfc562a27e099719d413287bc8d1d24deb7 < fa0f61cc1d828178aa921475a9b786e7fbb65ccb, >= 2.6.35
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available