CVE-2025-39897: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX metadata pointer retrieval Add proper error checking for dmaengine_desc_get_metadata_ptr() which can return an error pointer and lead to potential crashes or undefined behaviour if the pointer retrieval fails. Properly handle the error by unmapping DMA buffer, freeing the skb and returning early to prevent further processing with invalid data.

Affected products

  • Linux Linux Kernel: from 6.8, before 6.12.46 (fixed in 6.12.46); from 6.13, before 6.16.6 (fixed in 6.16.6); version 6.17 only

Published 2025-10-01. Last modified 2026-07-30.