Review reviewHigh

CVE-2025-39869

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: edma: Fix memory allocation size for queue_priority_map Fix a critical memory allocation bug in edma_setup_from_hw() where queue_priority_map was allocated with insufficient memory. The code declared queue_priority_map as s8 (*)[2] (pointer to array of 2 s8), but allocated memory using sizeof(s8) instead of the correct size. This caused out-of-bounds memory writes when accessing: queue_priority_map[i][0] = i; queue_priority_map[i][1] = i; The bug manifested as kernel crashes with "Oops - undefined instruction...

CVSS
7.1
EPSS
0.15%
4.63% percentile
CISA KEV
Not listed
Published
2025.09.23
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.15%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: edma: Fix memory allocation size for queue_priority_map Fix a critical memory allocation bug in edma_setup_from_hw() where queue_priority_map was allocated with insufficient memory. The code declared queue_priority_map as s8 (*)[2] (pointer to array of 2 s8), but allocated memory using sizeof(s8) instead of the correct size. This caused out-of-bounds memory writes when accessing: queue_priority_map[i][0] = i; queue_priority_map[i][1] = i; The bug manifested as kernel crashes with "Oops - undefined instruction...

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 2b6b3b7420190888793c49e97276e1e73bd7eaed < 7d4de60d6db02d9b01d5890d5156b04fad65d07a, >= 2b6b3b7420190888793c49e97276e1e73bd7eaed < d722de80ce037dccf6931e778f4a46499d51bdf9, >= 2b6b3b7420190888793c49e97276e1e73bd7eaed < 301a96cc4dc006c9a285913d301e681cfbf7edb6, >= 2b6b3b7420190888793c49e97276e1e73bd7eaed < 5e462fa0dfdb52b3983cf41532d3d4c7d63e2f93, >= 2b6b3b7420190888793c49e97276e1e73bd7eaed < 1baed10553fc8b388351d8fc803e3ae6f1a863bc, >= 2b6b3b7420190888793c49e97276e1e73bd7eaed < 069fd1688c57c0cc8a3de64d108579b31676f74b, >= 2b6b3b7420190888793c49e97276e1e73bd7eaed < d5e82f3f2c918d446df46e8d65f8083fd97cdec5, >= 2b6b3b7420190888793c49e97276e1e73bd7eaed < e63419dbf2ceb083c1651852209c7f048089ac0f, >= 4.4, >= 4.4 < 5.4.300, >= 5.5 < 5.10.245, >= 5.11 < 5.15.194, >= 5.16 < 6.1.153, >= 6.2 < 6.6.107, >= 6.7 < 6.12.48, >= 6.13 < 6.16.8, 6.17, 11.0
Fixed versions
5.4.300, 5.10.245, 5.15.194, 6.1.153, 6.6.107, 6.12.48, 6.16.8

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125
CVE-2025-39869 — Linux Linux, linux kernel, debian linux | SECUFOCUS NOW