VDB

DEBIAN-CVE-2025-39705

DEBIAN-CVE-2025-39705 PUBLISHED CVSS 5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a Null pointer dereference vulnerability [Why] A null pointer dereference vulnerability exists in the AMD display driver's (DC module) cleanup function dc_destruct(). When display control context (dc->ctx) construction fails (due to memory allocation failure), this pointer remains NULL. During subsequent error handling when dc_destruct() is called, there's no NULL check before dereferencing the perf_trace member (dc->ctx->perf_trace), causing a kernel null pointer dereference crash. [How] Check if dc->ctx is non-NULL before dereferencing. (Updated commit text and removed unnecessary error message) (cherry picked from commit 9dd8e2ba268c636c240a918e0a31e6feaee19404)

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:13linux6.12.38-1, 6.12.43-1, 6.12.43-1
Debian:14linux6.12.69-1~bpo12+1, 6.12.73-1, 6.12.73-1~bpo12+1
Debian:11linux5.10.209-2, 6.18.8-1, 6.18.9-1~bpo13+1
Debian:12linux6.1.135-1, 6.1.137-1, 6.1.139-1

Timeline

  • Sep 5, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›