CVE-2025-39817: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
Published Sep 16, 2025
·Updated
efivarfs: Fix slab-out-of-bounds in efivarfsdcompare
Affected Software
15 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.96.2-2
Microsoft cbl2 kernel 5.15.186.1-1
Linux Linux kernel>=3.8.2<5.4.298
Linux Linux kernel>=5.5<5.10.242
Linux Linux kernel>=5.11<5.15.191
Linux Linux kernel>=5.16<6.1.150
Linux Linux kernel>=6.2<6.6.104
Linux Linux kernel>=6.7<6.12.45
Linux Linux kernel>=6.13<6.16.5
Linux Linux kernel=6.17-rc1
Linux Linux kernel=6.17-rc2
Linux Linux kernel=6.17-rc3
Debian Debian Linux=11.0
IBM Cloud Pak for Data System<=11.3.0.2-IF1
Event History
Sep 16, 2025
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverity
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·02:03 PM
DescriptionSeverityAffected Software
Sep 20, 2025
Data Sourced
via Microsoft·01:08 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:08 AM
DescriptionSeverity
Updated
via Microsoft·08:08 AM
SeverityAffected Software
Aug 28, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-39817?
CVE-2025-39817 is classified as having a high severity due to its potential to cause a slab-out-of-bounds condition in the Linux kernel.
2
How do I fix CVE-2025-39817?
To fix CVE-2025-39817, update to the latest version of the Linux kernel that includes the patch for this vulnerability.
3
Which versions of the Linux kernel are affected by CVE-2025-39817?
CVE-2025-39817 affects Linux kernel versions prior to the patch release that resolves the slab-out-of-bounds issue.
4
What components are impacted by CVE-2025-39817?
CVE-2025-39817 specifically impacts the efivarfs component of the Linux kernel.
5
Is CVE-2025-39817 actively being exploited?
As of now, there are no public reports indicating that CVE-2025-39817 is being actively exploited in the wild.