{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-39897","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T07:20:57.146Z","datePublished":"2025-10-01T07:42:45.593Z","dateUpdated":"2026-08-05T12:05:58.614Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:05:58.614Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: xilinx: axienet: Add error handling for RX metadata pointer retrieval\n\nAdd proper error checking for dmaengine_desc_get_metadata_ptr() which\ncan return an error pointer and lead to potential crashes or undefined\nbehaviour if the pointer retrieval fails.\n\nProperly handle the error by unmapping DMA buffer, freeing the skb and\nreturning early to prevent further processing with invalid data."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable code is the RX completion callback of the Xilinx AXI Ethernet driver, reached purely by receiving a frame on the NIC, with no local access required. Any remote host able to send traffic that reaches the interface — including routed internet traffic to these FPGA-based embedded/industrial network devices — drives the faulting path.\nAC:L - In the affected configuration the error pointer is returned on every RX completion, so the very first packet the attacker sends deterministically triggers the fault — no race, no memory-layout grooming, no timing window. The attacker needs only to cause a single frame to arrive.\nPR:N - The RX DMA callback runs on unauthenticated inbound frames long before any protocol, socket, or credential check; the packet is not even parsed yet. No account, capability, or namespace access on the target is needed.\nUI:N - Packet reception and DMA completion processing are fully automatic within the driver's interrupt/tasklet path. No local user has to open, mount, configure, or interact with anything.\nS:U - The fault occurs in kernel code and its consequences are confined to the same kernel security authority — there is no hypervisor, IOMMU, or sandbox boundary crossed. This is a standard in-kernel driver defect.\nC:N - The dereference targets an ERR_PTR value in the permanently unmapped top page of the address space, so the load faults immediately and returns no data to the attacker. Execution never reaches the subsequent skb_put()/__netif_rx() that could have exposed adjacent heap contents, and the pointer value is fixed by driver state rather than attacker-controlled, so no read primitive exists.\nI:N - The bug is a single invalid read; there is no out-of-bounds write, no freed-object reuse, and no type confusion, so no kernel memory is modified. The faulting access aborts before any state-changing operation on the skb or the DMA ring.\nA:H - Dereferencing the error pointer causes a kernel oops from axienet_dma_rx_cb(), which executes in the dmaengine tasklet (softirq) context — a fatal exception in interrupt context that panics the machine. On affected systems this is a remotely triggerable, repeatable full denial of service of a network device that is often the only link to an embedded or industrial controller."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/xilinx/xilinx_axienet_main.c"],"versions":[{"version":"6a91b846af85a24241decd686269e8e038eb13d1","lessThan":"d0ecda6fdd840b406df6617b003b036f65dd8926","status":"affected","versionType":"git"},{"version":"6a91b846af85a24241decd686269e8e038eb13d1","lessThan":"92e2fc92bc4eb2bc0e84404316fbc02ddd0a3196","status":"affected","versionType":"git"},{"version":"6a91b846af85a24241decd686269e8e038eb13d1","lessThan":"8bbceba7dc5090c00105e006ce28d1292cfda8dd","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/xilinx/xilinx_axienet_main.c"],"versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","status":"unaffected","versionType":"semver"},{"version":"6.12.46","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.16.6","lessThanOrEqual":"6.16.*","status":"unaffected","versionType":"semver"},{"version":"6.17","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.12.46"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.16.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.17"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d0ecda6fdd840b406df6617b003b036f65dd8926"},{"url":"https://git.kernel.org/stable/c/92e2fc92bc4eb2bc0e84404316fbc02ddd0a3196"},{"url":"https://git.kernel.org/stable/c/8bbceba7dc5090c00105e006ce28d1292cfda8dd"}],"title":"net: xilinx: axienet: Add error handling for RX metadata pointer retrieval","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"id":"CVE-2025-39897","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-01-14T19:28:46.346333Z"}}}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-476","description":"CWE-476 NULL Pointer Dereference"}]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-01-14T19:33:13.992Z"}}]}}