CVE-2025-39728

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/04/2025
Last modified:
03/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> clk: samsung: Fix UBSAN panic in samsung_clk_init()<br /> <br /> With UBSAN_ARRAY_BOUNDS=y, I&amp;#39;m hitting the below panic due to<br /> dereferencing `ctx-&gt;clk_data.hws` before setting<br /> `ctx-&gt;clk_data.num = nr_clks`. Move that up to fix the crash.<br /> <br /> UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP<br /> <br /> Call trace:<br /> samsung_clk_init+0x110/0x124 (P)<br /> samsung_clk_init+0x48/0x124 (L)<br /> samsung_cmu_register_one+0x3c/0xa0<br /> exynos_arm64_register_cmu+0x54/0x64<br /> __gs101_cmu_top_of_clk_init_declare+0x28/0x60<br /> ...

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.236 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.180 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.134 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.87 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.23 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.13.11 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.14 (including) 6.14.2 (excluding)