CVE-2025-39846
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
19/09/2025
Last modified:
20/01/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()<br />
<br />
In __iodyn_find_io_region(), pcmcia_make_resource() is assigned to<br />
res and used in pci_bus_alloc_resource(). There is a dereference of res<br />
in pci_bus_alloc_resource(), which could lead to a NULL pointer<br />
dereference on failure of pcmcia_make_resource().<br />
<br />
Fix this bug by adding a check of res.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.35 (including) | 5.4.299 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.243 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.192 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.151 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.105 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.46 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.16.6 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2ee32c4c4f636e474cd8ab7c19a68cf36072ea93
- https://git.kernel.org/stable/c/44822df89e8f3386871d9cad563ece8e2fd8f0e7
- https://git.kernel.org/stable/c/4bd570f494124608a0696da070f00236a96fb610
- https://git.kernel.org/stable/c/5ff2826c998370bf7f9ae26fe802140d220e3510
- https://git.kernel.org/stable/c/b990c8c6ff50649ad3352507398e443b1e3527b2
- https://git.kernel.org/stable/c/ce3b7766276894d2fbb07e2047a171f9deb965de
- https://git.kernel.org/stable/c/d7286005e8fde0a430dc180a9f46c088c7d74483
- https://git.kernel.org/stable/c/fafa7450075f41d232bc785a4ebcbf16374f2076
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html



