Junglewise Threat Intelligence

CVE-2025-39788: Linux Kernel Exynos UFS driver out-of-bounds write

CVE-2025-39788 · Severity: high · CVSS 7.8 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's storage driver for Exynos-based devices (such as Google Pixel 6 series) could lead to system instability or unauthorized memory access. The issue stems from a mathematical error in how the system manages data transfer requests between the processor and the storage hardware. If exploited, a local attacker could potentially crash the system or gain elevated privileges, impacting the confidentiality and integrity of user data.

Technical details

An out-of-bounds write (CWE-787) exists in the Linux kernel's Universal Flash Storage (UFS) driver for Exynos SoCs (drivers/scsi/ufs/ufs-exynos.c). On specific hardware like the Google gs101, the number of UTP transfer request slots (nutrs) is 32. The driver performed a bitwise left shift of 1 by 'nutrs', but because the literal '1' is a 32-bit signed integer, shifting by 32 bits results in undefined behavior and an incorrect value of 0 being programmed into the HCI_UTRL_NEXUS_TYPE register. This can lead to memory corruption or system instability. The fix replaces the manual shift with the BIT() macro, which ensures correct type casting. The vulnerability is reachable by a local user with sufficient privileges to interact with the storage subsystem.

Affected products

  • Linux Linux Kernel 5.9 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-07-07: other: Initial patch submitted to Linux kernel mailing lists
  • 2025-09-11: disclosed: CVE published by kernel.org
  • 2025-09-11: patched: Fixes merged into various stable kernel branches

References

Related threats