Home

Description

In the Linux kernel, the following vulnerability has been resolved: efi: stmm: Fix incorrect buffer allocation method The communication buffer allocated by setup_mm_hdr() is later on passed to tee_shm_register_kernel_buf(). The latter expects those buffers to be contiguous pages, but setup_mm_hdr() just uses kmalloc(). That can cause various corruptions or BUGs, specifically since commit 9aec2fb0fd5e ("slab: allocate frozen pages"), though it was broken before as well. Fix this by using alloc_pages_exact() instead of kmalloc().

PUBLISHED Reserved 2025-04-16 | Published 2025-09-16 | Updated 2025-09-29 | Assigner Linux

Product status

Default status
unaffected

c44b6be62e8dd4ee0a308c36a70620613e6fc55f (git) before 77ff27ff0e4529a003c8a1c2492c111968c378d3
affected

c44b6be62e8dd4ee0a308c36a70620613e6fc55f (git) before 630c0e6064daf84f17aad1a7d9ca76b562e3fe47
affected

c44b6be62e8dd4ee0a308c36a70620613e6fc55f (git) before c5e81e672699e0c5557b2b755cc8f7a69aa92bff
affected

Default status
affected

6.8
affected

Any version before 6.8
unaffected

6.12.45 (semver)
unaffected

6.16.5 (semver)
unaffected

6.17 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/77ff27ff0e4529a003c8a1c2492c111968c378d3

git.kernel.org/...c/630c0e6064daf84f17aad1a7d9ca76b562e3fe47

git.kernel.org/...c/c5e81e672699e0c5557b2b755cc8f7a69aa92bff

cve.org (CVE-2025-39836)

nvd.nist.gov (CVE-2025-39836)

Download JSON