cbcvebase.
CVE-2025-39897
published 2025-10-01

CVE-2025-39897: In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX metadata pointer retrieval Add proper error…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX metadata pointer retrieval Add proper error checking for dmaengine_desc_get_metadata_ptr() which can return an error pointer and lead to potential crashes or undefined behaviour if the pointer retrieval fails. Properly handle the error by unmapping DMA buffer, freeing the skb and returning early to prevent further processing with invalid data.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.6-1 (forky)linux 6.16.6-1 (forky)
linuxlinux
linuxlinux>= 6a91b846af85a24241decd686269e8e038eb13d1 < d0ecda6fdd840b406df6617b003b036f65dd8926d0ecda6fdd840b406df6617b003b036f65dd8926
linuxlinux>= 6a91b846af85a24241decd686269e8e038eb13d1 < 92e2fc92bc4eb2bc0e84404316fbc02ddd0a319692e2fc92bc4eb2bc0e84404316fbc02ddd0a3196
linuxlinux>= 6a91b846af85a24241decd686269e8e038eb13d1 < 8bbceba7dc5090c00105e006ce28d1292cfda8dd8bbceba7dc5090c00105e006ce28d1292cfda8dd
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.6-16.16.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.13 < 6.16.66.16.6
linuxlinux_kernel>= 6.8 < 6.12.466.12.46

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.