CVE-2025-39836
Published: Sep 16, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: efi: stmm: Fix incorrect buffer allocation method The communication buffer allocated by setup_mm_hdr() is later on passed to tee_shm_register_kernel_buf(). The latter expects those buffers to be contiguous pages, but setup_mm_hdr() just uses kmalloc(). That can cause various corruptions or BUGs, specifically since commit 9aec2fb0fd5e ("slab: allocate frozen pages"), though it was broken before as well. Fix this by using alloc_pages_exact() instead of kmalloc().
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected c44b6be62e8dd4ee0a308c36a70620613e6fc55f - < 77ff27ff0e4529a003c8a1c2492c111968c378d3affected c44b6be62e8dd4ee0a308c36a70620613e6fc55f - < 630c0e6064daf84f17aad1a7d9ca76b562e3fe47affected c44b6be62e8dd4ee0a308c36a70620613e6fc55f - < c5e81e672699e0c5557b2b755cc8f7a69aa92bff |
Linux | Linux | affected 6.8unaffected 0 - < 6.8unaffected 6.12.45 - <= 6.12.*unaffected 6.16.5 - <= 6.16.*unaffected 6.17 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now