Error Handling Vulnerability in Xilinx AXIENET on Linux Kernel
CVE-2025-39897

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
1 October 2025

What is CVE-2025-39897?

A vulnerability exists in the Xilinx AXIENET driver within the Linux kernel that impacts the processing of DMA engine metadata pointers. If the retrieval of a metadata pointer fails, it may return an error pointer, potentially leading to system crashes or undefined behavior. Proper error handling has been implemented to mitigate this risk, including unmapping the DMA buffer and freeing the associated skb before further processing to ensure invalid data does not compromise system integrity.

Affected Version(s)

Linux 6a91b846af85a24241decd686269e8e038eb13d1

Linux 6a91b846af85a24241decd686269e8e038eb13d1 < 92e2fc92bc4eb2bc0e84404316fbc02ddd0a3196

Linux 6a91b846af85a24241decd686269e8e038eb13d1 < 8bbceba7dc5090c00105e006ce28d1292cfda8dd

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-39897 : Error Handling Vulnerability in Xilinx AXIENET on Linux Kernel