PT-2025-40094 · Linux+4 · Linux Kernel+4

Published

2025-01-01

·

Updated

2026-05-26

·

CVE-2025-39920

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The do validate mem() function lacks error handling for the add interval() call. A failure in kmalloc() within add interval() could lead to a null pointer being added to a linked list, resulting in an illegal memory access during a subsequent call to sub interval(). The patch addresses this by adding error handling to add interval(), causing the function to return early with an error code if add interval() fails.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-68046
BDU:2025-15667
CVE-2025-39920
DLA-4327-1
DLA-4328-1
ECHO-B4AC-9451-3BCC
OESA-2025-2532
OESA-2025-2536
OESA-2025-2537
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu