PT-2025-40080 · Linux+1 · Linux Kernel+1

Published

2025-10-01

·

Updated

2025-10-01

·

CVE-2025-39906

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel where unbinding of the GPU could leave the OEM I2C adapter registered. This could lead to a null pointer dereference when applications attempt to access the invalid device. The issue was addressed by removing the OEM I2C adapter upon completion.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-39906

Affected Products

Astra Linux
Linux Kernel