CVE-2025-39774
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-39774 is a vulnerability discovered in the Linux kernel, specifically affecting the RZ/G2L ADC driver (rzg2l_adc). The issue was disclosed on September 11, 2025, and involves a timing-related problem in the driver's runtime PM implementation (NVD).

Technical details

The vulnerability occurs when stress-testing the system by repeatedly unbinding and binding the ADC device in a loop, particularly when the ADC serves as a supplier for another device (such as a thermal hardware block). The issue manifests when the ADC device is runtime-resumed immediately after runtime PM is enabled, triggered by its consumer. Since the driver data (drvdata) is not set before enabling runtime PM, and the driver's runtime PM callbacks depend on this data, the system can crash (NVD, Ubuntu).

Impact

When exploited, this vulnerability can lead to system crashes, potentially affecting system stability and availability. The issue is particularly relevant in systems utilizing the RZ/G2L ADC driver with runtime power management features (NVD).

Mitigation and workarounds

The fix involves setting the driver data (drvdata) immediately after it is allocated and before enabling runtime PM. This ensures that the necessary data is available when the runtime PM callbacks are invoked (NVD).

Community reactions

Ubuntu has classified this vulnerability with a 'Medium' priority rating, indicating moderate severity in their security assessment (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61729HIGH7.5
  • DockerDocker
  • go
NoYesDec 02, 2025
CVE-2025-66293HIGH7.1
  • OpenJDK JDKOpenJDK JDK
  • java-17-openjdk-headless-slowdebug
NoNoDec 03, 2025
CVE-2025-39665MEDIUM6.9
  • Linux DebianLinux Debian
  • nagvis
NoNoDec 03, 2025
CVE-2025-61727MEDIUM6.5
  • DockerDocker
  • golang-1.24
NoYesDec 03, 2025
CVE-2025-66453MEDIUM5.5
  • JavaJava
  • org.mozilla:rhino
NoYesDec 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management