PT-2025-40071 · Xilinx+4 · Xilinx Axienet+4
Published
2025-09-03
·
Updated
2026-04-20
·
CVE-2025-39897
CVSS v2.0
5.7
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel's networking subsystem, specifically within the Xilinx Axienet driver. Insufficient error handling during retrieval of RX metadata pointers can lead to crashes or unpredictable behavior. The issue arises when
dmaengine desc get metadata ptr() fails to obtain a valid pointer. The fix involves adding error checking, unmapping DMA buffers, freeing the skb, and preventing further processing with invalid data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Ubuntu
Xilinx Axienet