Executive brief
A vulnerability in the Linux kernel's AMD display driver could allow a local user to crash the system. The issue occurs when the system attempts to manage High-bandwidth Digital Content Protection (HDCP) for displays, but fails to handle cases where no active displays are found. This can lead to a system instability or a complete kernel crash (denial of service).
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel's AMD display driver (drm/amd/display) within the mod_hdcp_hdcp1_create_session() function. The root cause is a failure to validate the return value of get_first_active_display(), which returns NULL if the display list is empty. An attacker with local access could potentially trigger this condition to cause a kernel oops and denial of service. The issue has been resolved by adding a null pointer check that returns MOD_HDCP_STATUS_DISPLAY_NOT_FOUND when no active display is detected. Fixes have been backported to multiple stable kernel branches including 5.15.y, 6.1.y, 6.6.y, 6.12.y, and 6.16.y.
Affected products
- Linux Linux Kernel 5.8 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-07-23: other: Vulnerability fixed in upstream code
- 2025-09-05: disclosed: NVD Published Date
- 2025-09-05: advisory: CVE-2025-39675 published by kernel.org
References
- https://git.kernel.org/stable/c/2af45aadb7b5d3852c76e2d1e985289ada6f48bf
- https://git.kernel.org/stable/c/2ee86b764c54e0d6a5464fb023b630fdf20869cd
- https://git.kernel.org/stable/c/7a2ca2ea64b1b63c8baa94a8f5deb70b2248d119
- https://git.kernel.org/stable/c/857b8387a9777e42b36e0400be99b54c251eaf9a
- https://git.kernel.org/stable/c/97fc94c5fd3c6ac5a13e457d38ee247737b8c4bd
- https://git.kernel.org/stable/c/ee0373b20bb67b1f00a1b25ccd24c8ac996b6446
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html