
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39794 was disclosed on September 12, 2025, affecting the Linux kernel. The vulnerability is related to the ARM Tegra platform's IRAM memory handling, specifically involving the use of memcpy operations (NVD).
The vulnerability occurs when Kasan (Kernel Address Sanitizer) attempts to check memory boundaries during normal memcpy operations when writing to IRAM in the ARM Tegra platform. This causes the kernel to crash, indicating a potential memory safety issue (NVD).
When exploited, this vulnerability can cause kernel crashes, potentially leading to system instability and denial of service on affected ARM Tegra systems (NVD).
The issue has been resolved by implementing I/O memcpy for writing to IRAM instead of using normal memcpy operations. This change prevents Kasan from crashing the kernel during boundary checks (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."