Resource management error in Linux kernel - CVE-2025-39818
Published: September 16, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the thc_i2c_subip_regs_save() and thc_i2c_subip_regs_restore() functions in drivers/hid/intel-thc-hid/intel-thc/intel-thc-dev.c. A local user can perform a denial of service (DoS) attack.
Affected software
Ubuntu
linux (Ubuntu package)
linux-realtime-6.14 (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws-6.14 (Ubuntu package)
linux-gcp-6.14 (Ubuntu package)
How to mitigate CVE-2025-39818
linux-realtime-6.14 (Ubuntu package) - update to 6.14.0-1016.16~24.04.1
linux-azure (Ubuntu package) - addressed in versions 6.14.0-1017.17, 6.14.0-1017.17~24.04.1
linux-aws-6.14 (Ubuntu package) - update to 6.14.0-1017.17~24.04.1
linux-gcp-6.14 (Ubuntu package) - addressed in versions 6.14.0-1018.18, 6.14.0-1020.21~24.04.1