PT-2025-36316 · Nxp Semiconductors +1 · Imx8Ulp +2

Published

2025-09-05

·

Updated

2025-09-06

·

CVE-2025-39722

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.

**Name of the Vulnerable Software and Affected Versions:**

Linux kernel (affected versions not specified)

**Description:**

A flaw exists in the Linux kernel's crypto/caam module that can lead to a system crash during suspend operations on iMX8QM and iMX8ULP SoCs. This occurs because the CAAM on these systems is managed by another ARM core (SECO on iMX8QM and Secure Enclave on iMX8ULP) which reserves access to register page 0. The vulnerability is triggered when suspend operations attempt to access this reserved page. A new state variable, `no page0`, has been introduced to track whether page 0 is reserved, preventing access during suspend.

**Recommendations:**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2025-39722

Affected Products

Linux Kernel
Imx8Qm
Imx8Ulp