
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39747 is a vulnerability discovered in the Linux kernel affecting the drm/msm driver component. The issue was disclosed on September 11, 2025, and involves improper error handling in the msm_ioctl_gem_info_set_metadata() function (NVD Database).
The vulnerability exists in the msm_ioctl_gem_info_set_metadata() function of the Linux kernel's DRM/MSM driver. The issue stems from inadequate error handling for krealloc failures, which could potentially lead to NULL pointer dereference. The fix implements proper error handling by returning -ENOMEM when krealloc fails and explicitly avoids using __GFP_NOFAIL due to potential deadlock risks and allocation constraints (NVD Database).
The vulnerability could potentially lead to NULL pointer dereference in the Linux kernel's DRM/MSM driver, which might result in system crashes or denial of service conditions (NVD Database).
The vulnerability has been patched in the Linux kernel by implementing proper error handling for krealloc failures in the msm_ioctl_gem_info_set_metadata() function. The fix has been documented in the kernel patchwork system (NVD Database).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."