PT-2025-38544 · Asus+2 · Asus Machines+2

Published

2025-09-19

·

Updated

2025-09-19

·

CVE-2025-39837

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The asus wmi register driver() function may be called concurrently from multiple drivers, leading to race conditions in list operations that can corrupt memory and cause system instability on some ASUS machines. Additionally, error handling was missing, failing to unregister ACPI LPS0 device operations in error scenarios. The issue is addressed by introducing a mutex in acpi wmi register driver() and * unregister driver(), and adding a call to asus s2idle check unregister() in the error path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2025-14113
CVE-2025-39837

Affected Products

Asus Machines
Astra Linux
Linux Kernel