CVE-2025-39674
Linux Debian vulnerability analysis and mitigation

Overview

A null pointer dereference vulnerability was discovered in the Linux kernel's SCSI UFS driver (CVE-2025-39674). The issue affects the ESI (Enhanced System Interrupt) configuration in the UFS-QCOM driver, which is a performance optimization feature providing dedicated interrupts per MCQ hardware queue. The vulnerability was disclosed on September 5, 2025 (NVD).

Technical details

The vulnerability occurs when platformdevicemsiinitandallocirqs() in ufsqcomconfigesi() fails (returns -EINVAL) but the code uses _free() macro for automatic cleanup to free MSI resources that were never successfully allocated. This leads to a null pointer dereference at virtual address 0x0000000000000008. The issue specifically affects the ESI/MSI feature, which is an optional performance optimization feature for UFS MCQ (NVD).

Impact

The vulnerability results in a kernel null pointer dereference which can cause system crashes and denial of service conditions. Since ESI is an optional feature, UFS MCQ functionality should still work without it, though potentially with reduced performance (NVD).

Mitigation and workarounds

The fix involves restructuring the ESI configuration to attempt MSI allocation first, before any other resource allocation, and implementing explicit cleanup instead of using the __free() macro to avoid cleanup of unallocated resources. The fix has been tested on SM8750 platform with MCQ enabled, both with and without Platform ESI support (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-65430MEDIUM5.4
  • Linux DebianLinux Debian
  • django-allauth
NoNoDec 15, 2025
CVE-2025-67897MEDIUM5.3
  • Linux DebianLinux Debian
  • rust-sequoia-openpgp
NoYesDec 14, 2025
CVE-2025-67899LOW2.9
  • Linux DebianLinux Debian
  • uriparser
NoNoDec 14, 2025
CVE-2025-65431N/AN/A
  • Linux DebianLinux Debian
  • django-allauth
NoNoDec 15, 2025
CVE-2025-9615N/AN/A
  • Linux DebianLinux Debian
  • network-manager
NoNoDec 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management