Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: efi: stmm: Fix incorrect buffer allocation method The communication buffer allocated by setup_mm_hdr() is later on passed to tee_shm_register_kernel_buf(). The latter expects those buffers to be contiguous pages, but setup_mm_hdr() just uses kmalloc(). That can cause various corruptions or BUGs, specifically since commit 9aec2fb0fd5e ("slab: allocate frozen pages"), though it was broken before as well. Fix this by using alloc_pages_exact() instead of kmalloc().
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.8, < 6.12.45 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/630c0e6064daf84f17aad1a7d9ca76b562e3fe47Patch
- https://git.kernel.org/stable/c/77ff27ff0e4529a003c8a1c2492c111968c378d3Patch
- https://git.kernel.org/stable/c/c5e81e672699e0c5557b2b755cc8f7a69aa92bffPatch
FAQ
What is CVE-2025-39836?
CVE-2025-39836 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: efi: stmm: Fix incorrect buffer allocation method The communication buffer allocated by setup_mm_hdr() is later on passed to tee_s...
How severe is CVE-2025-39836?
CVE-2025-39836 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-39836?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.