CVE-2025-39837Out-of-bounds Write in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 94.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateSep 22

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: Fix racy registrations asus_wmi_register_driver() may be called from multiple drivers concurrently, which can lead to the racy list operations, eventually corrupting the memory and hitting Oops on some ASUS machines. Also, the error handling is missing, and it forgot to unregister ACPI lps0 dev ops in the error case. This patch covers those issues by introducing a simple mutex at acpi_wmi_register_driv

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel6.166.16.6+1
Debianlinux/linux_kernel< 6.16.6-1
CVEListV5linux/linuxfeea7bd6b02d43a794e3f065650d89cf8d8e8e59e7a70326fb26b905cfc8fe2366113aa4394733ef+2
debiandebian/linux< linux 6.16.6-1 (forky)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g3gw-5g8v-fphj: In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: Fix racy registrations asus_wmi_register_driver() may be2025-09-22
OSV
CVE-2025-39837: In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: Fix racy registrations asus_wmi_register_driver() may be c2025-09-19

📋Vendor Advisories

2
Red Hat
kernel: platform/x86: asus-wmi: Fix racy registrations2025-09-19
Debian
CVE-2025-39837: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...2025
CVE-2025-39837 — Out-of-bounds Write in Linux | cvebase