PT-2025-40078 · Linux+1 · Linux Kernel+1
Mark
·
Published
2025-09-03
·
Updated
2025-10-01
·
CVE-2025-39904
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains an issue where the
kexec buf structure was declared without initialization. This could lead to the use of uninitialized memory, triggering a UBSAN (Undefined Behavior Sanitizer) warning when accessing an uninitialized field within the structure. The issue was identified during the loading of other segments and addressed by zero-initializing the kexec buf structure at its declaration to ensure all fields are properly set. The problem was initially observed on arm64 architectures and subsequently extended to riscv. The kexec buf structure is used in the kexec functionality, which allows for fast booting of a new kernel without going through the traditional bootloader process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Uninitialized Resource
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel