CVE-2025-39817 (GCVE-0-2025-39817)
Vulnerability from cvelistv5
Published
2025-09-16 13:00
Modified
2026-08-05 12:05
Summary
In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare Observed on kernel 6.6 (present on master as well): BUG: KASAN: slab-out-of-bounds in memcmp+0x98/0xd0 Call trace: kasan_check_range+0xe8/0x190 __asan_loadN+0x1c/0x28 memcmp+0x98/0xd0 efivarfs_d_compare+0x68/0xd8 __d_lookup_rcu_op_compare+0x178/0x218 __d_lookup_rcu+0x1f8/0x228 d_alloc_parallel+0x150/0x648 lookup_open.isra.0+0x5f0/0x8d0 open_last_lookups+0x264/0x828 path_openat+0x130/0x3f8 do_filp_open+0x114/0x248 do_sys_openat2+0x340/0x3c0 __arm64_sys_openat+0x120/0x1a0 If dentry->d_name.len < EFI_VARIABLE_GUID_LEN , 'guid' can become negative, leadings to oob. The issue can be triggered by parallel lookups using invalid filename: T1 T2 lookup_open ->lookup simple_lookup d_add // invalid dentry is added to hash list lookup_open d_alloc_parallel __d_lookup_rcu __d_lookup_rcu_op_compare hlist_bl_for_each_entry_rcu // invalid dentry can be retrieved ->d_compare efivarfs_d_compare // oob Fix it by checking 'guid' before cmp.
Impacted products
Vendor Product Version
Linux Linux Version: da27a24383b2b10bf6ebd0db29b325548aafecb4
Version: da27a24383b2b10bf6ebd0db29b325548aafecb4
Version: da27a24383b2b10bf6ebd0db29b325548aafecb4
Version: da27a24383b2b10bf6ebd0db29b325548aafecb4
Version: da27a24383b2b10bf6ebd0db29b325548aafecb4
Version: da27a24383b2b10bf6ebd0db29b325548aafecb4
Version: da27a24383b2b10bf6ebd0db29b325548aafecb4
Version: da27a24383b2b10bf6ebd0db29b325548aafecb4
Version: 688289c4b745c018b3449b4b4c5a2030083c8eaf
Version: 3.8.2   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T17:43:40.463Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC CN 4100",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V5.0",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-12T12:07:15.910Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
          }
        ],
        "x_adpType": "supplier"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-39817",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-10T20:40:28.646943Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-11T18:44:01.643Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/efivarfs/super.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "0f63fbabeaaaaaaf5b742a2f4c1b4590d50bf1f6",
              "status": "affected",
              "version": "da27a24383b2b10bf6ebd0db29b325548aafecb4",
              "versionType": "git"
            },
            {
              "lessThan": "794399019301944fd6d2e0d7a51b3327e26c410e",
              "status": "affected",
              "version": "da27a24383b2b10bf6ebd0db29b325548aafecb4",
              "versionType": "git"
            },
            {
              "lessThan": "568e7761279b99c6daa3002290fd6d8047ddb6d2",
              "status": "affected",
              "version": "da27a24383b2b10bf6ebd0db29b325548aafecb4",
              "versionType": "git"
            },
            {
              "lessThan": "d7f5e35e70507d10cbaff5f9e194ed54c4ee14f7",
              "status": "affected",
              "version": "da27a24383b2b10bf6ebd0db29b325548aafecb4",
              "versionType": "git"
            },
            {
              "lessThan": "925599eba46045930b850a98ae594d2e3028ac40",
              "status": "affected",
              "version": "da27a24383b2b10bf6ebd0db29b325548aafecb4",
              "versionType": "git"
            },
            {
              "lessThan": "c2925cd6207079c3f4d040d082515db78d63afbf",
              "status": "affected",
              "version": "da27a24383b2b10bf6ebd0db29b325548aafecb4",
              "versionType": "git"
            },
            {
              "lessThan": "71581a82f38e5a4d807d71fc1bb59aead80ccf95",
              "status": "affected",
              "version": "da27a24383b2b10bf6ebd0db29b325548aafecb4",
              "versionType": "git"
            },
            {
              "lessThan": "a6358f8cf64850f3f27857b8ed8c1b08cfc4685c",
              "status": "affected",
              "version": "da27a24383b2b10bf6ebd0db29b325548aafecb4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "688289c4b745c018b3449b4b4c5a2030083c8eaf",
              "versionType": "git"
            },
            {
              "lessThan": "3.9",
              "status": "affected",
              "version": "3.8.2",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/efivarfs/super.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "lessThan": "3.9",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.298",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.242",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.191",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.150",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.104",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.45",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.16.*",
              "status": "unaffected",
              "version": "6.16.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.17",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.298",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.242",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.191",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.150",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.104",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.45",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16.5",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.8.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nefivarfs: Fix slab-out-of-bounds in efivarfs_d_compare\n\nObserved on kernel 6.6 (present on master as well):\n\n  BUG: KASAN: slab-out-of-bounds in memcmp+0x98/0xd0\n  Call trace:\n   kasan_check_range+0xe8/0x190\n   __asan_loadN+0x1c/0x28\n   memcmp+0x98/0xd0\n   efivarfs_d_compare+0x68/0xd8\n   __d_lookup_rcu_op_compare+0x178/0x218\n   __d_lookup_rcu+0x1f8/0x228\n   d_alloc_parallel+0x150/0x648\n   lookup_open.isra.0+0x5f0/0x8d0\n   open_last_lookups+0x264/0x828\n   path_openat+0x130/0x3f8\n   do_filp_open+0x114/0x248\n   do_sys_openat2+0x340/0x3c0\n   __arm64_sys_openat+0x120/0x1a0\n\nIf dentry-\u003ed_name.len \u003c EFI_VARIABLE_GUID_LEN , \u0027guid\u0027 can become\nnegative, leadings to oob. The issue can be triggered by parallel\nlookups using invalid filename:\n\n  T1\t\t\tT2\n  lookup_open\n   -\u003elookup\n    simple_lookup\n     d_add\n     // invalid dentry is added to hash list\n\n\t\t\tlookup_open\n\t\t\t d_alloc_parallel\n\t\t\t  __d_lookup_rcu\n\t\t\t   __d_lookup_rcu_op_compare\n\t\t\t    hlist_bl_for_each_entry_rcu\n\t\t\t    // invalid dentry can be retrieved\n\t\t\t     -\u003ed_compare\n\t\t\t      efivarfs_d_compare\n\t\t\t      // oob\n\nFix it by checking \u0027guid\u0027 before cmp."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable `efivarfs_d_compare()` is reached only through local path-lookup syscalls (`openat`/`stat`) against the efivarfs mount at /sys/firmware/efi/efivars. There is no network or remote-peer input path into the dcache lookup for this filesystem.\nAC:L - `efivarfs_d_hash()` makes every name shorter than 36 bytes hash to the same value, so the attacker deterministically constructs the bucket collision and length match rather than guessing them, and both sides of the parallel-lookup race are attacker threads that can retry in a tight loop indefinitely. No condition outside the attacker\u0027s control is required.\nPR:L - The efivarfs root directory is mode 0755 and lookup requires only MAY_EXEC, so any unprivileged local user can issue the two concurrent `openat()` calls; `-\u003elookup` is `simple_lookup` with no name validation and no write permission needed. No capability, and no root, is involved.\nUI:N - The attacker drives both racing lookups themselves with no victim participation. efivarfs being mounted is a default-deployment property of UEFI systems (systemd mounts it at boot), not an action a user must be tricked into performing.\nS:U - The out-of-bounds read stays within kernel slab memory under the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The negative `guid` is promoted to a ~2^64 `size_t`, giving a length-unbounded read that walks past the `dentry_cache` object into arbitrary adjacent kernel heap memory, and the attacker controls the comparison bytes on both sides so the early-exit point of `memcmp` acts as an oracle on that memory. Per kernel guidance an unbounded OOB read scores High.\nI:N - `efivarfs_d_compare()` performs only `memcmp`/`strncasecmp` reads and writes nothing; a false dentry match that could redirect a lookup to the wrong EFI variable would require ~2^64 consecutive matching bytes, which faults long before it could occur.\nA:H - The KASAN trace in the fix commit documents a slab-out-of-bounds abort, and the unbounded read readily runs off the slab page into unmapped memory, producing an oops or panic (and an immediate panic under KASAN/panic_on_oops). The attacker can retrigger it at will from an unprivileged loop."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:05:23.813Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0f63fbabeaaaaaaf5b742a2f4c1b4590d50bf1f6"
        },
        {
          "url": "https://git.kernel.org/stable/c/794399019301944fd6d2e0d7a51b3327e26c410e"
        },
        {
          "url": "https://git.kernel.org/stable/c/568e7761279b99c6daa3002290fd6d8047ddb6d2"
        },
        {
          "url": "https://git.kernel.org/stable/c/d7f5e35e70507d10cbaff5f9e194ed54c4ee14f7"
        },
        {
          "url": "https://git.kernel.org/stable/c/925599eba46045930b850a98ae594d2e3028ac40"
        },
        {
          "url": "https://git.kernel.org/stable/c/c2925cd6207079c3f4d040d082515db78d63afbf"
        },
        {
          "url": "https://git.kernel.org/stable/c/71581a82f38e5a4d807d71fc1bb59aead80ccf95"
        },
        {
          "url": "https://git.kernel.org/stable/c/a6358f8cf64850f3f27857b8ed8c1b08cfc4685c"
        }
      ],
      "title": "efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-39817",
    "datePublished": "2025-09-16T13:00:17.776Z",
    "dateReserved": "2025-04-16T07:20:57.138Z",
    "dateUpdated": "2026-08-05T12:05:23.813Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T17:43:40.463Z\"}}, {\"affected\": [{\"vendor\": \"Siemens\", \"product\": \"SIMATIC CN 4100\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"lessThan\": \"V5.0\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unknown\"}], \"x_adpType\": \"supplier\", \"references\": [{\"url\": \"https://cert-portal.siemens.com/productcert/html/ssa-032379.html\"}], \"providerMetadata\": {\"orgId\": \"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e\", \"shortName\": \"siemens-SADP\", \"dateUpdated\": \"2026-05-12T12:07:15.910Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-39817\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-06-10T20:40:28.646943Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-06-11T17:37:21.240Z\"}}], \"cna\": {\"title\": \"efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.1, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H\"}}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"da27a24383b2b10bf6ebd0db29b325548aafecb4\", \"lessThan\": \"0f63fbabeaaaaaaf5b742a2f4c1b4590d50bf1f6\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"da27a24383b2b10bf6ebd0db29b325548aafecb4\", \"lessThan\": \"794399019301944fd6d2e0d7a51b3327e26c410e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"da27a24383b2b10bf6ebd0db29b325548aafecb4\", \"lessThan\": \"568e7761279b99c6daa3002290fd6d8047ddb6d2\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"da27a24383b2b10bf6ebd0db29b325548aafecb4\", \"lessThan\": \"d7f5e35e70507d10cbaff5f9e194ed54c4ee14f7\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"da27a24383b2b10bf6ebd0db29b325548aafecb4\", \"lessThan\": \"925599eba46045930b850a98ae594d2e3028ac40\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"da27a24383b2b10bf6ebd0db29b325548aafecb4\", \"lessThan\": \"c2925cd6207079c3f4d040d082515db78d63afbf\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"da27a24383b2b10bf6ebd0db29b325548aafecb4\", \"lessThan\": \"71581a82f38e5a4d807d71fc1bb59aead80ccf95\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"da27a24383b2b10bf6ebd0db29b325548aafecb4\", \"lessThan\": \"a6358f8cf64850f3f27857b8ed8c1b08cfc4685c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"688289c4b745c018b3449b4b4c5a2030083c8eaf\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"3.8.2\", \"lessThan\": \"3.9\", \"versionType\": \"semver\"}], \"programFiles\": [\"fs/efivarfs/super.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"3.9\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"3.9\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.298\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.242\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.191\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.150\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.104\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.45\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.16.5\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.16.*\"}, {\"status\": \"unaffected\", \"version\": \"6.17\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"fs/efivarfs/super.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/0f63fbabeaaaaaaf5b742a2f4c1b4590d50bf1f6\"}, {\"url\": \"https://git.kernel.org/stable/c/794399019301944fd6d2e0d7a51b3327e26c410e\"}, {\"url\": \"https://git.kernel.org/stable/c/568e7761279b99c6daa3002290fd6d8047ddb6d2\"}, {\"url\": \"https://git.kernel.org/stable/c/d7f5e35e70507d10cbaff5f9e194ed54c4ee14f7\"}, {\"url\": \"https://git.kernel.org/stable/c/925599eba46045930b850a98ae594d2e3028ac40\"}, {\"url\": \"https://git.kernel.org/stable/c/c2925cd6207079c3f4d040d082515db78d63afbf\"}, {\"url\": \"https://git.kernel.org/stable/c/71581a82f38e5a4d807d71fc1bb59aead80ccf95\"}, {\"url\": \"https://git.kernel.org/stable/c/a6358f8cf64850f3f27857b8ed8c1b08cfc4685c\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nefivarfs: Fix slab-out-of-bounds in efivarfs_d_compare\\n\\nObserved on kernel 6.6 (present on master as well):\\n\\n  BUG: KASAN: slab-out-of-bounds in memcmp+0x98/0xd0\\n  Call trace:\\n   kasan_check_range+0xe8/0x190\\n   __asan_loadN+0x1c/0x28\\n   memcmp+0x98/0xd0\\n   efivarfs_d_compare+0x68/0xd8\\n   __d_lookup_rcu_op_compare+0x178/0x218\\n   __d_lookup_rcu+0x1f8/0x228\\n   d_alloc_parallel+0x150/0x648\\n   lookup_open.isra.0+0x5f0/0x8d0\\n   open_last_lookups+0x264/0x828\\n   path_openat+0x130/0x3f8\\n   do_filp_open+0x114/0x248\\n   do_sys_openat2+0x340/0x3c0\\n   __arm64_sys_openat+0x120/0x1a0\\n\\nIf dentry-\u003ed_name.len \u003c EFI_VARIABLE_GUID_LEN , \u0027guid\u0027 can become\\nnegative, leadings to oob. The issue can be triggered by parallel\\nlookups using invalid filename:\\n\\n  T1\\t\\t\\tT2\\n  lookup_open\\n   -\u003elookup\\n    simple_lookup\\n     d_add\\n     // invalid dentry is added to hash list\\n\\n\\t\\t\\tlookup_open\\n\\t\\t\\t d_alloc_parallel\\n\\t\\t\\t  __d_lookup_rcu\\n\\t\\t\\t   __d_lookup_rcu_op_compare\\n\\t\\t\\t    hlist_bl_for_each_entry_rcu\\n\\t\\t\\t    // invalid dentry can be retrieved\\n\\t\\t\\t     -\u003ed_compare\\n\\t\\t\\t      efivarfs_d_compare\\n\\t\\t\\t      // oob\\n\\nFix it by checking \u0027guid\u0027 before cmp.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.298\", \"versionStartIncluding\": \"3.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.242\", \"versionStartIncluding\": \"3.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.191\", \"versionStartIncluding\": \"3.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.150\", \"versionStartIncluding\": \"3.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.104\", \"versionStartIncluding\": \"3.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.45\", \"versionStartIncluding\": \"3.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.16.5\", \"versionStartIncluding\": \"3.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.17\", \"versionStartIncluding\": \"3.9\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"3.8.2\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-07-30T05:57:48.376Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-39817\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-07-30T05:57:48.376Z\", \"dateReserved\": \"2025-04-16T07:20:57.138Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2025-09-16T13:00:17.776Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…