cbcvebase.
CVE-2025-39995
published 2025-10-15

CVE-2025-39995: In the Linux kernel, the following vulnerability has been resolved: media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe The…

PriorityP421high7.8
EPSS
0.22%
12.3th percentile
In the Linux kernel, the following vulnerability has been resolved: media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe The state->timer is a cyclic timer that schedules work_i2c_poll and delayed_work_enable_hotplug, while rearming itself. Using timer_delete() fails to guarantee the timer isn't still running when destroyed, similarly cancel_delayed_work() cannot ensure delayed_work_enable_hotplug has terminated if already executing. During probe failure after timer initialization, these may continue running as orphans and reference the already-freed tc358743_state object through tc358743_irq_poll_timer. The following is the trace captured by KASAN. BUG: KASAN: slab-use-after-free in __run_timer_base.part.0+0x7d7/0x8c0 Write of size 8 at addr ffff88800ded83c8 by task swapper/1/0 ... Call Trace: dump_stack_lvl+0x55/0x70 print_report+0xcf/0x610 ? __pfx_sched_balance_find_src_group+0x10/0x10 ? __run_timer_base.part.0+0x7d7/0x8c0 kasan_report+0xb8/0xf0 ? __run_timer_base.part.0+0x7d7/0x8c0 __run_timer_base.part.0+0x7d7/0x8c0 ? rcu_sched_clock_irq+0xb06/0x27d0 ? __pfx___run_timer_base.part.0+0x10/0x10 ? try_to_wake_up+0xb15/0x1960 ? tmigr_update_events+0x280/0x740 ? _raw_spin_lock_irq+0x80/0xe0 ? __pfx__raw_spin_lock_irq+0x10/0x10 tmigr_handle_remote_up+0x603/0x7e0 ? __pfx_tmigr_handle_remote_up+0x10/0x10 ? sched_balance_trigger+0x98/0x9f0 ? sched_tick+0x221/0x5a0 ? _raw_spin_lock_irq+0x80/0xe0 ? __pfx__raw_spin_lock_irq+0x10/0x10 ? tick_nohz_handler+0x339/0x440 ? __pfx_tmigr_handle_remote_up+0x10/0x10 __walk_groups.isra.0+0x42/0x150 tmigr_handle_remote+0x1f4/0x2e0 ? __pfx_tmigr_handle_remote+0x10/0x10 ? ktime_get+0x60/0x140 ? lapic_next_event+0x11/0x20 ? clockevents_program_event+0x1d4/0x2a0 ? hrtimer_interrupt+0x322/0x780 handle_softirqs+0x16a/0x550 irq_exit_rcu+0xaf/0xe0 sysvec_apic_timer_interrupt+0x70/0x80 ... Allocated by task 141: kasan_save_stack+0x24/0x50 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x7f/0x90 __kmalloc_node_track_ca

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < 9205fb6e617a1c596d9a9ad2a160ee696e09d5209205fb6e617a1c596d9a9ad2a160ee696e09d520
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < 70913586c717dd25cfbade7a418e92cc9c99398a70913586c717dd25cfbade7a418e92cc9c99398a
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < 663faf1179db9663a3793c75e9bc869358bad910663faf1179db9663a3793c75e9bc869358bad910
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < 3d17701c156579969470e58b3a906511f8bc018d3d17701c156579969470e58b3a906511f8bc018d
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < 228d06c4cbfc750f1216a3fd91b4693b0766d2f6228d06c4cbfc750f1216a3fd91b4693b0766d2f6
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < f92181c0e13cad9671d07b15be695a97fc2534a3f92181c0e13cad9671d07b15be695a97fc2534a3
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < f3f3f00bcabbd2ce0a77a2ac7a6797b8646bfd8bf3f3f00bcabbd2ce0a77a2ac7a6797b8646bfd8b
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < 2610617effb4454d2f1c434c011ccb5cc71407112610617effb4454d2f1c434c011ccb5cc7140711
linuxlinux>= d32d98642de66048f9534a05f3641558e811bbc9 < 79d10f4f21a92e459b2276a77be62c59c1502c9d79d10f4f21a92e459b2276a77be62c59c1502c9d
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.11-16.16.11-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 4.3.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1566.1.156
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.16.116.16.11
linuxlinux_kernel>= 6.17.0 < 6.17.16.17.1
linuxlinux_kernel>= 6.2.0 < 6.6.1116.6.111

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.