cbcvebase.
CVE-2025-39902
published 2025-10-01

CVE-2025-39902: In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err() object_err()…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err() object_err() reports details of an object for further debugging, such as the freelist pointer, redzone, etc. However, if the pointer is invalid, attempting to access object metadata can lead to a crash since it does not point to a valid object. One known path to the crash is when alloc_consistency_checks() determines the pointer to the allocated object is invalid because of a freelist corruption, and calls object_err() to report it. The debug code should report and handle the corruption gracefully and not crash in the process. In case the pointer is NULL or check_valid_pointer() returns false for the pointer, only print the pointer value and skip accessing metadata.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux>= 81819f0fc8285a2a5a921c019e3e3d7b6169d225 < 872f2c34ff232af1e65ad2df86d61163c8ffad42872f2c34ff232af1e65ad2df86d61163c8ffad42
linuxlinux>= 81819f0fc8285a2a5a921c019e3e3d7b6169d225 < f66012909e7bf383fcdc5850709ed5716073fdc4f66012909e7bf383fcdc5850709ed5716073fdc4
linuxlinux>= 81819f0fc8285a2a5a921c019e3e3d7b6169d225 < 7e287256904ee796c9477e3ec92b07f236481ef37e287256904ee796c9477e3ec92b07f236481ef3
linuxlinux>= 81819f0fc8285a2a5a921c019e3e3d7b6169d225 < 1f0797f17927b5cad0fb7eced422f9a7c30a31911f0797f17927b5cad0fb7eced422f9a7c30a3191
linuxlinux>= 81819f0fc8285a2a5a921c019e3e3d7b6169d225 < 0ef7058b4dc6fcef622ac23b45225db57f17b83f0ef7058b4dc6fcef622ac23b45225db57f17b83f
linuxlinux>= 81819f0fc8285a2a5a921c019e3e3d7b6169d225 < dda6ec365ab04067adae40ef17015db447e90736dda6ec365ab04067adae40ef17015db447e90736
linuxlinux>= 81819f0fc8285a2a5a921c019e3e3d7b6169d225 < 3baa1da473e6e50281324ff1d332d1a07a3bb02e3baa1da473e6e50281324ff1d332d1a07a3bb02e
linuxlinux>= 81819f0fc8285a2a5a921c019e3e3d7b6169d225 < b4efccec8d06ceb10a7d34d7b1c449c569d53770b4efccec8d06ceb10a7d34d7b1c449c569d53770
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.6-16.16.6-1
linuxlinux_kernel>= 0 < 5.15.0-163.1735.15.0-163.173
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 2.6.22 < 5.4.2995.4.299
linuxlinux_kernel>= 5.11 < 5.15.1925.15.192
linuxlinux_kernel>= 5.16 < 6.1.1516.1.151
linuxlinux_kernel>= 5.5 < 5.10.2435.10.243
linuxlinux_kernel>= 6.13 < 6.16.66.16.6
linuxlinux_kernel>= 6.2 < 6.6.1056.6.105

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM