Executive brief
A vulnerability exists in the Linux kernel's PCMCIA subsystem, which manages legacy expansion cards for laptops and embedded devices. A technical error in how the system allocates hardware resources could allow a local user to cause a system crash (kernel panic). This results in a denial-of-service, potentially disrupting operations or causing data loss on the affected machine.
Technical details
A NULL pointer dereference exists in the __iodyn_find_io_region() function within drivers/pcmcia/rsrc_iodyn.c. The vulnerability occurs because the return value of pcmcia_make_resource() is assigned to a pointer that is subsequently dereferenced in pci_bus_alloc_resource() without a prior NULL check. If pcmcia_make_resource() fails and returns NULL, the kernel will attempt to access an invalid memory address, leading to a kernel panic. This is a local attack vector requiring low privileges. Patches have been released across multiple stable kernel branches to add the necessary validation check.
Affected products
- Linux Linux Kernel 2.6.35 to 5.4.299, 5.5 to 5.10.243, 5.11 to 5.15.192, 5.16 to 6.1.151, 6.2 to 6.6.105, 6.7 to 6.12.46, 6.13 to 6.16.6
Timeline
- 2025-08-12: other: Patch authored
- 2025-09-19: disclosed: CVE published
- 2025-09-19: patched: Initial patch merged into stable trees
References
- https://git.kernel.org/stable/c/2ee32c4c4f636e474cd8ab7c19a68cf36072ea93
- https://git.kernel.org/stable/c/44822df89e8f3386871d9cad563ece8e2fd8f0e7
- https://git.kernel.org/stable/c/4bd570f494124608a0696da070f00236a96fb610
- https://git.kernel.org/stable/c/5ff2826c998370bf7f9ae26fe802140d220e3510
- https://git.kernel.org/stable/c/b990c8c6ff50649ad3352507398e443b1e3527b2
- https://git.kernel.org/stable/c/ce3b7766276894d2fbb07e2047a171f9deb965de
- https://git.kernel.org/stable/c/d7286005e8fde0a430dc180a9f46c088c7d74483