DEBIAN-CVE-2025-39705
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a Null pointer dereference vulnerability [Why] A null pointer dereference vulnerability exists in the AMD display driver's (DC module) cleanup function dc_destruct(). When display control context (dc->ctx) construction fails (due to memory allocation failure), this pointer remains NULL. During subsequent error handling when dc_destruct() is called, there's no NULL check before dereferencing the perf_trace member (dc->ctx->perf_trace), causing a kernel null pointer dereference crash. [How] Check if dc->ctx is non-NULL before dereferencing. (Updated commit text and removed unnecessary error message) (cherry picked from commit 9dd8e2ba268c636c240a918e0a31e6feaee19404)
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | linux | 6.12.38-1, 6.12.43-1, 6.12.43-1 |
| Debian:14 | linux | 6.12.69-1~bpo12+1, 6.12.73-1, 6.12.73-1~bpo12+1 |
| Debian:11 | linux | 5.10.209-2, 6.18.8-1, 6.18.9-1~bpo13+1 |
| Debian:12 | linux | 6.1.135-1, 6.1.137-1, 6.1.139-1 |
Timeline
- Sep 5, 2025 CVE Published
- Apr 28, 2026 CVE Updated