Junglewise Threat Intelligence

CVE-2025-39789: Linux Kernel missing error checks in x86 AEGIS crypto implementation

CVE-2025-39789 · Severity: high · CVSS 7.3 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's cryptographic component for x86 processors. The system fails to properly check for errors when allocating memory during certain encryption tasks. This could potentially allow a local user to cause system instability or gain unauthorized access to sensitive information.

Technical details

The vulnerability is located in arch/x86/crypto/aegis128-aesni-glue.c within the Linux kernel. The root cause is the lack of error checking for skcipher_walk functions (specifically skcipher_walk_aead_encrypt, skcipher_walk_aead_decrypt, and skcipher_walk_done), which are capable of failing during memory allocation. An attacker with local access could potentially exploit this lack of validation to trigger undefined behavior or memory corruption. The issue has been resolved by adding the necessary return value checks to ensure the cryptographic process halts if an allocation error occurs. Patches are available in the stable kernel tree.

Affected products

  • Linux Linux Kernel 4.18 to 6.16.4

Timeline

  • 2025-09-11: disclosed
  • 2025-09-11: advisory
  • 2025-07-18: patched

References

Related threats