SB20250916149 - Out-of-bounds read in Linux kernel scsi ufs driver
Published: September 16, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2025-39788)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the exynos_ufs_post_link() function in drivers/scsi/ufs/ufs-exynos.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/01510a9e8222f11cce064410f3c2fcf0756c0a08
- https://git.kernel.org/stable/c/01aad16c2257ab8ff33b152b972c9f2e1af47912
- https://git.kernel.org/stable/c/098b2c8ee208c77126839047b9e6e1925bb35baa
- https://git.kernel.org/stable/c/5b9f1ef293428ea9c0871d96fcec2a87c4445832
- https://git.kernel.org/stable/c/6d53b2a134da77eb7fe65c5c7c7a3c193539a78a
- https://git.kernel.org/stable/c/c1f025da8f370a015e412b55cbcc583f91de8316
- https://git.kernel.org/stable/c/dc8fb963742f1a38d284946638f9358bdaa0ddee