CVE-2025-39774
Published: Sep 11, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: iio: adc: rzg2l_adc: Set driver data before enabling runtime PM When stress-testing the system by repeatedly unbinding and binding the ADC device in a loop, and the ADC is a supplier for another device (e.g., a thermal hardware block that reads temperature through the ADC), it may happen that the ADC device is runtime-resumed immediately after runtime PM is enabled, triggered by its consumer. At this point, since drvdata is not yet set and the driver's runtime PM callbacks rely on it, a crash can occur. To avoid this, set drvdata just after it was allocated.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 89ee8174e8c8db0efc75b26f2307114b38d61354 - < e7ce902db071a7b3e696a43d6e14ca57360deee6affected 89ee8174e8c8db0efc75b26f2307114b38d61354 - < c69e13965f26b8058f538ea8bdbd2d7718cf1fbe |
Linux | Linux | affected 6.14unaffected 0 - < 6.14unaffected 6.16.4 - <= 6.16.*unaffected 6.17 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now