
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39787 is a buffer over-read vulnerability in the Linux kernel's Qualcomm MDT (Modem Device Tree) loader component (soc/qcom/mdt_loader). The flaw arises because the MDT loader fails to validate the firmware buffer size and ELF header fields (e_phentsize, e_shentsize) before iterating over the ELF header, allowing reads past the end of the allocated buffer. It affects Linux kernel versions 4.11 through 6.16.x across multiple stable branches, as well as Debian Linux 11.0 and Microsoft Azure Linux 3 (kernel 6.6.96.2-2). Disclosed on September 11, 2025, it carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, Feedly).
The root cause is improper validation of input size (CWE-1284 / out-of-bounds read) in the mdt_loader subsystem. When the MDT loader is invoked by clients other than remoteproc — which performs its own ELF sanitization — no check is made to ensure the firmware buffer is large enough to contain the full ELF header, nor are e_phentsize and e_shentsize validated for expected step sizes during header traversal. A local attacker with low privileges can supply a crafted firmware binary with malformed ELF header fields, causing the kernel to read beyond the firmware buffer boundary. The vulnerability was introduced at kernel commit 2aad40d911eeb7dcac91c669f2762a28134f0eb1 and is present across all stable branches from 4.11 onward until the respective patched versions (Feedly, Microsoft MSRC).
Successful exploitation results in a denial-of-service condition — specifically kernel panics or system crashes — due to out-of-bounds memory reads in kernel space. There is no confidentiality or integrity impact reported; the availability impact is rated High. The vulnerability is most significant in multi-user environments or systems that load firmware from untrusted sources, where a low-privileged local user could trigger a kernel crash and render the system unavailable (Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation as of the time of writing. The vulnerability requires local access with low privileges, limiting its remote attack surface. The EPSS score is approximately 0.024% (very low probability of exploitation in the near term), and it is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (Feedly).
Update the Linux kernel to a patched stable version. Fixed versions are available across all affected branches: 5.4.297, 5.10.241, 5.15.190, 6.1.149, 6.6.103, 6.12.44, and 6.16.4. Microsoft released a patch for Azure Linux 3 on September 13, 2025. As a workaround, restrict local user access on systems that load Qualcomm firmware via the MDT loader, and disable untrusted firmware loading where operationally feasible. Prioritize patching systems with multi-user access or those that process firmware from untrusted sources (Microsoft MSRC, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."