Junglewise Threat Intelligence

CVE-2025-39783: Linux Kernel out-of-bounds write in PCI endpoint configfs

CVE-2025-39783 · Severity: high · CVSS 7.8 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's PCI endpoint component could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when certain hardware drivers are removed, leading to memory corruption. This could impact system availability and the integrity of operations on affected devices.

Technical details

A use-after-free vulnerability exists in the Linux kernel's PCI endpoint subsystem due to incorrect list head handling in the pci_epf_remove_cfs() function. The code incorrectly calls list_del() on a list head (epf_group) instead of a list entry during the teardown of an endpoint function driver. This results in an out-of-bounds write or slab-use-after-free, as identified by KASAN warnings during module removal (rmmod). A local attacker with sufficient privileges to manage kernel modules or trigger driver teardown could exploit this to cause a kernel panic or achieve local privilege escalation. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 4.18 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-06-24: patched: Initial patch authored by Damien Le Moal
  • 2025-09-11: advisory: CVE-2025-39783 published

References