Junglewise Threat Intelligence

CVE-2025-39729: Linux Kernel CCP uninitialized pointer dereference in SEV

CVE-2025-39729 · Severity: medium · CVSS 5.5 · Published 2025-09-07

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Crypto Co-Processor (CCP) driver, which manages hardware-accelerated encryption and Secure Encrypted Virtualization (SEV). An error in how the system handles internal error messages could lead to a system crash or instability. This typically affects servers using AMD SEV technology for protecting virtual machines. Patches have been released to ensure the system handles these internal errors safely.

Technical details

A vulnerability exists in the Linux kernel's 'drivers/crypto/ccp/sev-dev.c' within the '__sev_platform_init_locked()' function. The issue stems from accessing an uninitialized error pointer during the SEV_CMD_DF_FLUSH command execution. Specifically, the code previously assumed the 'error' pointer could be null but attempted to dereference it when reporting failures, leading to a kernel oops or crash. This is classified as CWE-824 (Access of Uninitialized Pointer). The fix involves properly initializing error variables and ensuring they are correctly passed to command handlers. Patches are available in various stable kernel branches including 6.16.1 and later.

Affected products

  • Linux Linux Kernel 6.16, 6.17

Timeline

  • 2025-05-28: other: Patch authored
  • 2025-09-07: disclosed: CVE published

References

Related threats