PT-2025-38564 · Linux+5 · Linux Kernel+5

Published

2025-04-16

·

Updated

2026-05-07

·

CVE-2025-39857

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 6.17.0-rc2+ and earlier
Description A NULL pointer dereference issue was identified in the smc ib is sg need sync() function within the smc module of the Linux kernel. This occurs when the software RoCE device is used, resulting in ibdev->dma device being a null pointer. A fix was implemented by adding null pointer detection to prevent this issue.
Recommendations Linux kernel versions prior to 6.17.0-rc2+ should be updated.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-67532
BDU:2025-13449
CVE-2025-39857
DLA-4328-1
DSA-6008-1
DSA-6009-1
ECHO-863F-9580-A194
INFESA-2025_0006
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03601-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3725-1
SUSE-SU-2025:3751-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu