
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39803 is a vulnerability discovered in the Linux kernel, specifically in the SCSI UFS core component. The issue was disclosed on September 15, 2025, affecting the UIC completion interrupt handling in the ufshcd_uic_cmd_compl() function. The vulnerability primarily impacts Linux kernel systems that utilize the UFS (Universal Flash Storage) subsystem (NVD, Debian Tracker).
The vulnerability occurs when the UIC completion interrupt is disabled while a UIC command is being processed. Upon re-enabling the UIC completion interrupt, an UIC interrupt is triggered, causing a WARN_ON_ONCE(!cmd) statement to be hit. This issue was addressed by removing the kernel warning from the ufshcd_uic_cmd_compl() function (NVD, Debian Tracker).
The impact of this vulnerability appears to be limited to system logging and debugging functionality, as it primarily involves a kernel warning mechanism. The issue affects systems running vulnerable versions of the Linux kernel with UFS storage implementations (Debian Tracker).
The vulnerability has been resolved through a kernel patch that removes the problematic WARN_ON_ONCE() call from the ufshcd_uic_cmd_compl() function. Various Linux distributions have incorporated the fix, including Debian's bullseye, bookworm, and trixie releases (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."