Junglewise Threat Intelligence

CVE-2025-39794: Linux Kernel crash in ARM Tegra reset handler

CVE-2025-39794 · Severity: medium · CVSS 5.5 · Published 2025-09-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's support for NVIDIA Tegra processors could allow a local user to cause a system crash. The issue occurs when the system attempts to manage internal memory during CPU reset operations. This could lead to a denial-of-service, impacting the availability of devices using these specific ARM-based chips.

Technical details

A vulnerability exists in the Linux kernel's ARM Tegra architecture support within 'arch/arm/mach-tegra/reset.c'. The 'tegra_cpu_reset_handler_enable' function used a standard 'memcpy' to write to Internal RAM (IRAM). When KernelAddressSanitizer (KASAN) is enabled, it attempts to perform boundary checks on this operation, which results in a kernel crash because standard memory functions are not appropriate for I/O memory regions. An attacker with local access could potentially trigger this condition to cause a denial-of-service. The fix replaces 'memcpy' with 'memcpy_toio' to correctly handle the I/O memory access.

Affected products

  • Linux Linux Kernel 3.4 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-05-22: other: Initial patch authored
  • 2025-09-12: disclosed: CVE published
  • 2025-08-28: patched: Patch committed to stable branches

References