CVE-2025-39739
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39739 was disclosed on September 11, 2025, affecting the Linux kernel. The vulnerability is related to the IOMMU/ARM-SMMU-QCOM component, specifically involving the SM6115 MDSS compatibility issue. This vulnerability was identified in the QRB4210 RB2 platform which is based on SM4250/SM6115 (NVD).

Technical details

The vulnerability manifests as unhandled context faults during boot in the ARM-SMMU component. The system generates numerous SMMU unhandled context faults with specific fault signatures including FSR=0x402 and FSYNR0=00320021. These faults occur due to missing SM6115 MDSS compatible entries in the clients compatible list (NVD).

Impact

The vulnerability leads to failed initialization of multiple components including the lontium lt9611uxc, GPU, and DPU. This results in binding failures for MDSS components that are triggered by lt9611uxc. The issue causes system instability and potential boot failures on affected systems (NVD).

Mitigation and workarounds

The vulnerability has been resolved by adding the SM6115 MDSS compatible to the clients compatible list. This fix addresses the SMMU context faults and prevents the component initialization failures (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management