cbcvebase.
CVE-2025-39807
published 2025-09-16

CVE-2025-39807: In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Add error handling for old state CRTC in atomic_disable Introduce error…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Add error handling for old state CRTC in atomic_disable Introduce error handling to address an issue where, after a hotplug event, the cursor continues to update. This situation can lead to a kernel panic due to accessing the NULL `old_state->crtc`. E,g. Unable to handle kernel NULL pointer dereference at virtual address Call trace: mtk_crtc_plane_disable+0x24/0x140 mtk_plane_atomic_update+0x8c/0xa8 drm_atomic_helper_commit_planes+0x114/0x2c8 drm_atomic_helper_commit_tail_rpm+0x4c/0x158 commit_tail+0xa0/0x168 drm_atomic_helper_commit+0x110/0x120 drm_atomic_commit+0x8c/0xe0 drm_atomic_helper_update_plane+0xd4/0x128 __setplane_atomic+0xcc/0x110 drm_mode_cursor_common+0x250/0x440 drm_mode_cursor_ioctl+0x44/0x70 drm_ioctl+0x264/0x5d8 __arm64_sys_ioctl+0xd8/0x510 invoke_syscall+0x6c/0xe0 do_el0_svc+0x68/0xe8 el0_svc+0x34/0x60 el0t_64_sync_handler+0x1c/0xf8 el0t_64_sync+0x180/0x188 Adding NULL pointer checks to ensure stability by preventing operations on an invalid CRTC state.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.5-1 (forky)linux 6.16.5-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 40b5b4ba8ed87c0bfb6268c10589777652ebde4c < 7d5cc22efa44e0fe321ce195c71c3d7da211fbb27d5cc22efa44e0fe321ce195c71c3d7da211fbb2
linuxlinux>= 6.12.40 < 6.12.456.12.45
linuxlinux>= 6.15.8 < 6.166.16
linuxlinux>= d208261e9f7c66960587b10473081dc1cecbe50b < 9a94e9d8b50bcfe89693bc899a54d3866d86e9739a94e9d8b50bcfe89693bc899a54d3866d86e973
linuxlinux>= d208261e9f7c66960587b10473081dc1cecbe50b < 0c6b24d70da21201ed009a2aca740d2dfddc7ab50c6b24d70da21201ed009a2aca740d2dfddc7ab5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.5-16.16.5-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.12.40 < 6.12.456.12.45
linuxlinux_kernel>= 6.15.8 < 6.166.16
linuxlinux_kernel>= 6.16.1 < 6.16.56.16.5
ubuntulinux-xilinx

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.