
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39897 is a vulnerability discovered in the Linux kernel affecting the Xilinx AXI Ethernet driver. The vulnerability was disclosed on October 1, 2025, and involves improper error handling for RX metadata pointer retrieval in the network subsystem (NVD, Ubuntu).
The vulnerability stems from insufficient error checking in the dmaengine_desc_get_metadata_ptr() function within the Xilinx AXI Ethernet driver. When the pointer retrieval fails, it can return an error pointer which, if not properly handled, may lead to potential crashes or undefined behavior. The issue has been assigned a CVSS v3.1 base score of 5.5 with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (RedHat).
If exploited, this vulnerability can result in system crashes or undefined behavior in systems using the affected Xilinx AXI Ethernet driver. The impact is primarily focused on system availability, with no direct effect on confidentiality or integrity (RedHat).
The vulnerability has been resolved by adding proper error handling for the dmaengine_desc_get_metadata_ptr() function. The fix includes unmapping the DMA buffer, freeing the skb, and returning early to prevent further processing with invalid data (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."