cbcvebase.
CVE-2025-39823
published 2025-09-16

CVE-2025-39823: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that come from guest min and dest_id are…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that come from guest min and dest_id are guest-controlled indices. Using array_index_nospec() after the bounds checks clamps these values to mitigate speculative execution side-channels.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux>= 4180bf1b655a791a0a6ef93a2ffffc762722c782 < 72777fc31aa7ab2ce00f44bfa3929c6eabbeaf4872777fc31aa7ab2ce00f44bfa3929c6eabbeaf48
linuxlinux>= 4180bf1b655a791a0a6ef93a2ffffc762722c782 < 31a0ad2f60cb4816e06218b63e695eb72ce7497431a0ad2f60cb4816e06218b63e695eb72ce74974
linuxlinux>= 4180bf1b655a791a0a6ef93a2ffffc762722c782 < d51e381beed5e2f50f85f49f6c90e023754efa12d51e381beed5e2f50f85f49f6c90e023754efa12
linuxlinux>= 4180bf1b655a791a0a6ef93a2ffffc762722c782 < 33e974c2d5a82b2f9d9ba0ad9cbaabc1c8e3985f33e974c2d5a82b2f9d9ba0ad9cbaabc1c8e3985f
linuxlinux>= 4180bf1b655a791a0a6ef93a2ffffc762722c782 < f49161646e03d107ce81a99c6ca5da682fe5fb69f49161646e03d107ce81a99c6ca5da682fe5fb69
linuxlinux>= 4180bf1b655a791a0a6ef93a2ffffc762722c782 < 67a05679621b7f721bdba37a5d18665d3aceb69567a05679621b7f721bdba37a5d18665d3aceb695
linuxlinux>= 4180bf1b655a791a0a6ef93a2ffffc762722c782 < f57a4bd8d6cb5af05b8ac1be9098e249034639fbf57a4bd8d6cb5af05b8ac1be9098e249034639fb
linuxlinux>= 4180bf1b655a791a0a6ef93a2ffffc762722c782 < c87bd4dd43a624109c3cc42d843138378a7f4548c87bd4dd43a624109c3cc42d843138378a7f4548
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.5-16.16.5-1
linuxlinux_kernel>= 0 < 5.15.0-163.1735.15.0-163.173
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 4.19 < 5.4.2985.4.298
linuxlinux_kernel>= 5.11 < 5.15.1915.15.191
linuxlinux_kernel>= 5.16 < 6.1.1506.1.150
linuxlinux_kernel>= 5.5 < 5.10.2425.10.242
linuxlinux_kernel>= 6.13 < 6.16.56.16.5
linuxlinux_kernel>= 6.2 < 6.6.1046.6.104

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
CVE-2025-39823 — Improper Validation of Array Index | cvebase