Junglewise Threat Intelligence

CVE-2025-39846: Linux Kernel NULL pointer dereference in PCMCIA __iodyn_find_io_region

CVE-2025-39846 · Severity: medium · CVSS 5.5 · Published 2025-09-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's PCMCIA subsystem, which manages legacy expansion cards for laptops and embedded devices. A technical error in how the system allocates hardware resources could allow a local user to cause a system crash (kernel panic). This results in a denial-of-service, potentially disrupting operations or causing data loss on the affected machine.

Technical details

A NULL pointer dereference exists in the __iodyn_find_io_region() function within drivers/pcmcia/rsrc_iodyn.c. The vulnerability occurs because the return value of pcmcia_make_resource() is assigned to a pointer that is subsequently dereferenced in pci_bus_alloc_resource() without a prior NULL check. If pcmcia_make_resource() fails and returns NULL, the kernel will attempt to access an invalid memory address, leading to a kernel panic. This is a local attack vector requiring low privileges. Patches have been released across multiple stable kernel branches to add the necessary validation check.

Affected products

  • Linux Linux Kernel 2.6.35 to 5.4.299, 5.5 to 5.10.243, 5.11 to 5.15.192, 5.16 to 6.1.151, 6.2 to 6.6.105, 6.7 to 6.12.46, 6.13 to 6.16.6

Timeline

  • 2025-08-12: other: Patch authored
  • 2025-09-19: disclosed: CVE published
  • 2025-09-19: patched: Initial patch merged into stable trees

References

Related threats