Junglewise Threat Intelligence

CVE-2025-39939: Linux Kernel memory corruption in s390 IOMMU identity domain

CVE-2025-39939 · Severity: high · CVSS 7.8 · Published 2025-10-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's s390 architecture support could lead to memory corruption. The issue occurs when the system attempts to read performance statistics for certain hardware configurations, potentially allowing a local user to crash the system or gain unauthorized access to data. This affects systems using s390 hardware with specific IOMMU identity domain settings.

Technical details

An out-of-bounds write vulnerability exists in drivers/iommu/s390-iommu.c within the Linux kernel. The function zpci_get_iommu_ctrs() incorrectly attempts to convert an identity domain to an s390_domain structure using to_s390_domain(). Because identity domains are not backed by this specific structure, the conversion results in an invalid memory address. Subsequent operations on this address, such as zeroing or reading via sysfs, lead to memory corruption or global-out-of-bounds access. The issue is reachable by local users via sysfs reads when a device is configured with an IOMMU identity domain. Patches have been released in kernel versions 6.16.9 and 6.17.

Affected products

  • Linux Linux Kernel 6.15 to 6.16.8

Timeline

  • 2025-10-04: disclosed
  • 2025-10-04: advisory
  • 2025-09-25: patched

References

Related threats