CVE-2025-39809: HID: intel-thc-hid: intel-quicki2c: Fix ACPI dsd ICRS/ISUB length

Published Sep 16, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

HID: intel-thc-hid: intel-quicki2c: Fix ACPI dsd ICRS/ISUB length

The QuickI2C ACPI DSD methods return ICRS and ISUB data with a trailing byte, making the actual length is one more byte than the structs defined.

It caused stack-out-of-bounds and kernel crash:

kernel: BUG: KASAN: stack-out-of-bounds in quicki2cacpigetdsdproperty.constprop.0+0x111/0x1b0 [intelquicki2c] kernel: Write of size 12 at addr ffff888106d1f900 by task kworker/u33:2/75 kernel: kernel: CPU: 3 UID: 0 PID: 75 Comm: kworker/u33:2 Not tainted 6.16.0+ #3 PREEMPT(voluntary) kernel: Workqueue: async asyncrunentryfn kernel: Call Trace: kernel: <TASK> kernel: dumpstacklvl+0x76/0xa0 kernel: printreport+0xd1/0x660 kernel: ? pfxrawspinlockirqsave+0x10/0x10 kernel: ? kasanslabfree+0x5d/0x80 kernel: ? kasanaddrtoslab+0xd/0xb0 kernel: kasanreport+0xe1/0x120 kernel: ? quicki2cacpigetdsdproperty.constprop.0+0x111/0x1b0 [intelquicki2c] kernel: ? quicki2cacpigetdsdproperty.constprop.0+0x111/0x1b0 [intelquicki2c] kernel: kasancheckrange+0x11c/0x200 kernel: asanmemcpy+0x3b/0x80 kernel: quicki2cacpigetdsdproperty.constprop.0+0x111/0x1b0 [intelquicki2c] kernel: ? pfxquicki2cacpigetdsdproperty.constprop.0+0x10/0x10 [intelquicki2c] kernel: quicki2cgetacpiresources+0x237/0x730 [intelquicki2c] [...] kernel: </TASK> kernel: kernel: The buggy address belongs to stack of task kworker/u33:2/75 kernel: and is located at offset 48 in frame: kernel: quicki2cgetacpiresources+0x0/0x730 [intelquicki2c] kernel: kernel: This frame has 3 objects: kernel: [32, 36) 'hiddescaddr' kernel: [48, 59) 'i2cparam' kernel: [80, 224) 'i2cconfig'

ACPI DSD methods return:

\SB.PC00.THC0.ICRS Buffer 000000003fdc947b 001 Len 0C = 0A 00 80 1A 06 00 00 00 00 00 00 00 \SB.PC00.THC0.ISUB Buffer 00000000f2fcbdc4 001 Len 91 = 00 00 00 00 00 00 00 00 00 00 00 00

Adding reserved padding to quicki2csubipacpiparameter/config.

Affected Software

6 affected components
Intel QuickI2C>=6.16.0
Linux Linux kernel>=6.16.0
Linux Linux kernel>=6.14<6.16.5
Linux Linux kernel=6.17-rc1
Linux Linux kernel=6.17-rc2
Linux Linux kernel=6.17-rc3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel (QuickI2C intel_quicki2c) to a version that resolves this vulnerability.

    Patch Fix ACPI dsd ICRS/ISUB length
  2. Configuration

    Apply the kernel change that adds reserved padding to quicki2c_subip_acpi_parameter/config so the ACPI _DSD ICRS/ISUB lengths match what the driver expects (prevents stack-out-of-bounds/kasan crash in quicki2c_acpi_get_dsd_property).

    intel_quicki2c ACPI _DSD parameter handling Adding reserved padding to quicki2c_subip_acpi_parameter/config = Add reserved padding

Event History

Sep 16, 2025
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverity
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-39809?

CVE-2025-39809 has been classified with a severity that can impact the functionality of the affected components.

2

How do I fix CVE-2025-39809?

To fix CVE-2025-39809, update your Intel QuickI2C and Linux kernel to version 6.16.0 or later.

3

What software is affected by CVE-2025-39809?

CVE-2025-39809 affects Intel QuickI2C and the Linux kernel starting from version 6.16.0.

4

What are the potential consequences of CVE-2025-39809?

The potential consequences of CVE-2025-39809 include incorrect data retrieval due to the trailing byte issue in the ACPI _DSD methods.

5

When was CVE-2025-39809 resolved?

CVE-2025-39809 was resolved in a patch released with the Linux kernel updates addressing the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203