CVE Database
/

CVE-2025-39823

Back to search

CVE-2025-39823

Published: Sep 16, 2025

Modified: May 12, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that come from guest min and dest_id are guest-controlled indices. Using array_index_nospec() after the bounds checks clamps these values to mitigate speculative execution side-channels.

VendorProductVersions

Linux

Linux

affected
4180bf1b655a791a0a6ef93a2ffffc762722c782 - < 72777fc31aa7ab2ce00f44bfa3929c6eabbeaf48
affected
4180bf1b655a791a0a6ef93a2ffffc762722c782 - < 31a0ad2f60cb4816e06218b63e695eb72ce74974
affected
4180bf1b655a791a0a6ef93a2ffffc762722c782 - < d51e381beed5e2f50f85f49f6c90e023754efa12
affected
4180bf1b655a791a0a6ef93a2ffffc762722c782 - < 33e974c2d5a82b2f9d9ba0ad9cbaabc1c8e3985f
affected
4180bf1b655a791a0a6ef93a2ffffc762722c782 - < f49161646e03d107ce81a99c6ca5da682fe5fb69

+3 more versions

Linux

Linux

affected
4.19
unaffected
0 - < 4.19
unaffected
5.4.298 - <= 5.4.*
unaffected
5.10.242 - <= 5.10.*
unaffected
5.15.191 - <= 5.15.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now