Executive brief
A vulnerability in the Linux kernel's Trusted Execution Environment (TEE) subsystem could allow a local user to crash the system. The issue occurs during specific power management operations, such as system shutdown or hibernation, when the kernel incorrectly handles memory references. This results in a system 'panic' or crash, leading to a denial of service.
Technical details
A NULL pointer dereference exists in the tee_shm_put function within the Linux kernel's TEE (Trusted Execution Environment) driver. The vulnerability is triggered when __optee_disable_shm_cache calls tee_shm_free with a NULL shared memory pointer returned by reg_pair_to_ptr. This occurs during device shutdown or hibernation sequences (e.g., via sysfs state_store). A local attacker with sufficient privileges to trigger power state changes or interact with TEE device drivers could cause a kernel panic (Oops). The fix introduces a NULL check for the shm pointer and its associated context in tee_shm_put.
Affected products
- Linux Linux Kernel 4.14.261 to 4.15, 4.19.224 to 4.20, 5.4.170 to 5.5, 5.10.89 to 5.10.243, 5.15.12 to 5.15.192, 5.16.1 to 6.1.151, 6.2 to 6.6.105, 6.7 to 6.12.46, 6.13 to 6.16.6
Timeline
- 2025-07-23: other: Patch authored
- 2025-09-09: patched: Patch committed to stable trees
- 2025-09-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/25e315bc8ad363bd1194e49062f183ad4011957e
- https://git.kernel.org/stable/c/4377eac565c297fdfccd2f8e9bf94ee84ff6172f
- https://git.kernel.org/stable/c/5e07a4235bb85d9ef664411e4ff4ac34783c18ff
- https://git.kernel.org/stable/c/963fca19fe34c496e04f7dd133b807b76a5434ca
- https://git.kernel.org/stable/c/add1ecc8f3ad8df22e3599c5c88d7907cc2a3079
- https://git.kernel.org/stable/c/e4a718a3a47e89805c3be9d46a84de1949a98d5d
- https://git.kernel.org/stable/c/f266188603c34e6e234fb0dfc3185f0ba98d71b7