{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-39786",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-04-16T07:20:57.131Z",
        "datePublished": "2025-09-11T16:56:35.706Z",
        "dateUpdated": "2026-08-05T12:05:07.581Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:05:07.581Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad7173: fix channels index for syscalib_mode\n\nFix the index used to look up the channel when accessing the\nsyscalib_mode attribute. The address field is a 0-based index (same\nas scan_index) that it used to access the channel in the\nad7173_channels array throughout the driver. The channels field, on\nthe other hand, may not match the address field depending on the\nchannel configuration specified in the device tree and could result\nin an out-of-bounds access."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerability is reached purely through the IIO sysfs interface (`/sys/bus/iio/devices/iio:deviceN/in_voltageX-voltageY_sys_calibrat ion_mode`) on the local system. No network or physical bus access is needed — the attacker only needs to read/write a local sysfs file.\nAC:L - A single deterministic sysfs read or write triggers the out-of-bounds access; there is no race, no timing element, and no dependence on memory layout to reach the bug. The out-of-range index is baked in by ordinary device-tree configurations — the driver's own binding example (`diff-channels = <0 1>,<2 3>,<4 5>,<6 7>,<8 9>`) already yields indices 6 and 8 into a 6-element array.\nPR:L - `sys_calibration_mode` is created with mode 0644 by `__iio_device_attr_init()`, so any unprivileged local user can trigger the out-of-bounds heap read; the paired store handler gives the out-of-bounds write, which on the industrial/embedded deployments using this ADC is commonly delegated to a non-root calibration daemon via udev rules. No real root in the init namespace is required to reach the vulnerable code.\nUI:N - The attacker acts entirely on their own by opening the sysfs attribute; no victim action, mount, or device plug-in is required. The affected ADC is a permanently attached SPI device enumerated at boot.\nS:U - The out-of-bounds access corrupts and discloses adjacent kernel slab memory within the same kernel security authority. There is no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - The read path indexes up to 22 elements (≈548 bytes) past a heap allocation that can be as small as 24 bytes, reading bytes belonging to neighbouring slab objects and exposing their state through the enum attribute. Combined with heap grooming to place chosen objects adjacent to the `devm_kcalloc()` allocation, this leaks kernel heap contents.\nI:H - `ad7173_set_syscalib_mode()` performs an out-of-bounds *write* of a controlled 0/1 byte hundreds of bytes past the array, silently corrupting a live adjacent kernel slab object. A targeted single-byte heap overwrite of a neighbouring object's field is a classic primitive for escalating to control-flow hijack.\nA:H - Corrupting an adjacent slab object with the out-of-bounds write causes kernel oops/panic when that object is next used, and on CONFIG_KASAN or hardened builds the out-of-bounds access alone produces a splat that panics under `panic_on_warn`. The condition is repeatable at will."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/iio/adc/ad7173.c"
                    ],
                    "versions": [
                        {
                            "version": "031bdc8aee01b7b298159eee541844d8bff4467d",
                            "lessThan": "2def1a8691eb43654da0ae0d2fdb3722e20262a5",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "031bdc8aee01b7b298159eee541844d8bff4467d",
                            "lessThan": "0eb8d7b25397330beab8ee62c681975b79f37223",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/iio/adc/ad7173.c"
                    ],
                    "versions": [
                        {
                            "version": "6.14",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.14",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.16.4",
                            "lessThanOrEqual": "6.16.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.17",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.14",
                                    "versionEndExcluding": "6.16.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.14",
                                    "versionEndExcluding": "6.17"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/2def1a8691eb43654da0ae0d2fdb3722e20262a5"
                },
                {
                    "url": "https://git.kernel.org/stable/c/0eb8d7b25397330beab8ee62c681975b79f37223"
                }
            ],
            "title": "iio: adc: ad7173: fix channels index for syscalib_mode",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}