cbcvebase.
CVE-2025-39714
published 2025-09-05

CVE-2025-39714: In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Lock resolution while streaming When an program is streaming (ffplay) and…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Lock resolution while streaming When an program is streaming (ffplay) and another program (qv4l2) changes the TV standard from NTSC to PAL, the kernel crashes due to trying to copy to unmapped memory. Changing from NTSC to PAL increases the resolution in the usbtv struct, but the video plane buffer isn't adjusted, so it overflows. [hverkuil: call vb2_is_busy instead of vb2_is_streaming]

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux>= 0e0fe3958fdd13dbf55c3a787acafde6efd04272 < c35e7c7a004ef379a1ae7c7486d4829419acad1dc35e7c7a004ef379a1ae7c7486d4829419acad1d
linuxlinux>= 0e0fe3958fdd13dbf55c3a787acafde6efd04272 < ee7bade8b9244834229b12b6e1e724939bedd484ee7bade8b9244834229b12b6e1e724939bedd484
linuxlinux>= 0e0fe3958fdd13dbf55c3a787acafde6efd04272 < 5427dda195d6baf23028196fd55a0c90f66ffa615427dda195d6baf23028196fd55a0c90f66ffa61
linuxlinux>= 0e0fe3958fdd13dbf55c3a787acafde6efd04272 < ef9b3c22405192afaa279077ddd45a51db90b83def9b3c22405192afaa279077ddd45a51db90b83d
linuxlinux>= 0e0fe3958fdd13dbf55c3a787acafde6efd04272 < 3d83d0b5ae5045a7a246ed116b5f6c688a12f9e93d83d0b5ae5045a7a246ed116b5f6c688a12f9e9
linuxlinux>= 0e0fe3958fdd13dbf55c3a787acafde6efd04272 < c3d75524e10021aa5c223d94da4996640aed46c0c3d75524e10021aa5c223d94da4996640aed46c0
linuxlinux>= 0e0fe3958fdd13dbf55c3a787acafde6efd04272 < 9f886d21e235c4bd038cb20f6696084304197ab39f886d21e235c4bd038cb20f6696084304197ab3
linuxlinux>= 0e0fe3958fdd13dbf55c3a787acafde6efd04272 < 7e40e0bb778907b2441bff68d73c3eb6b6cd319f7e40e0bb778907b2441bff68d73c3eb6b6cd319f
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.5-16.16.5-1
linuxlinux_kernel>= 0 < 5.15.0-163.1735.15.0-163.173
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 3.14 < 5.4.2975.4.297
linuxlinux_kernel>= 5.11 < 5.15.1905.15.190
linuxlinux_kernel>= 5.16 < 6.1.1496.1.149
linuxlinux_kernel>= 5.5 < 5.10.2415.10.241
linuxlinux_kernel>= 6.13 < 6.16.46.16.4
linuxlinux_kernel>= 6.2 < 6.6.1036.6.103
linuxlinux_kernel>= 6.7 < 6.12.446.12.44

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM