CVE-2025-39707: drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities
drm/amdgpu: check if hubbub is NULL in debugfs/amdgpudmcapabilities
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In drm/amdgpu debugfs/amdgpu_dm_capabilities, check whether HUBBUB is NULL before accessing it to prevent a null dereference when HUBBUB structure initialization is absent on DCE hardware.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39707?
CVE-2025-39707 has a medium severity due to the potential for null dereference leading to application crashes.
How do I fix CVE-2025-39707?
To fix CVE-2025-39707, update your Linux kernel to a version where the vulnerability has been addressed.
Which versions of the Linux kernel are affected by CVE-2025-39707?
CVE-2025-39707 affects versions of the Linux kernel prior to the patch addressing this vulnerability.
What is the impact of CVE-2025-39707 on Linux systems?
The impact of CVE-2025-39707 could lead to system instability and potential crashes when accessing specific debugfs entries.
Is CVE-2025-39707 publicly known?
Yes, CVE-2025-39707 is a publicly disclosed vulnerability in the Linux kernel.