In the Linux kernel, the following vulnerability has been resolved:
media: venus: protect against spurious interrupts during probe
Make sure the interrupt handler is initialized before the interrupt is registered.
If the IRQ is registered before hfi_create(), it's possible that an interrupt fires before the handler setup is complete, leading to a NULL dereference.
This error condition has been observed during system boot on Rb3Gen2.
[
{
"deprecated": false,
"target": {
"file": "drivers/media/platform/qcom/venus/core.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"291490091787668948852466511828478721277",
"17036562235885979525445152211200960007",
"264184962489102313990068945312084971234",
"76244951398012903593103839663210503827",
"130216201250621863048219224306396190345",
"225727100582430506581531148611125341945",
"68709599485268602526514794068169301925",
"56738768408124153650131572446503490968",
"27866425754144168863135376115979607928"
]
},
"id": "CVE-2025-39709-05083e25",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3200144a2fa4209dc084a19941b9b203b43580f0",
"signature_version": "v1"
},
{
"deprecated": false,
"target": {
"file": "drivers/media/platform/qcom/venus/core.c",
"function": "venus_probe"
},
"digest": {
"function_hash": "16296212327911968136442873702834911939",
"length": 2697.0
},
"id": "CVE-2025-39709-4699d6ae",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@639eb587f977c02423f4762467055b23902b4131",
"signature_version": "v1"
},
{
"deprecated": false,
"target": {
"file": "drivers/media/platform/qcom/venus/core.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"291490091787668948852466511828478721277",
"17036562235885979525445152211200960007",
"264184962489102313990068945312084971234",
"76244951398012903593103839663210503827",
"130216201250621863048219224306396190345",
"225727100582430506581531148611125341945",
"68709599485268602526514794068169301925",
"56738768408124153650131572446503490968",
"27866425754144168863135376115979607928"
]
},
"id": "CVE-2025-39709-8ac6c75e",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@639eb587f977c02423f4762467055b23902b4131",
"signature_version": "v1"
},
{
"deprecated": false,
"target": {
"file": "drivers/media/platform/qcom/venus/core.c",
"function": "venus_probe"
},
"digest": {
"function_hash": "328960557336829478340425296346217161791",
"length": 2879.0
},
"id": "CVE-2025-39709-8aed44fb",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3200144a2fa4209dc084a19941b9b203b43580f0",
"signature_version": "v1"
}
]