VYPR
Medium severity5.5NVD Advisory· Published Sep 11, 2025· Updated Jun 17, 2026

CVE-2025-39774

CVE-2025-39774

Description

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: rzg2l_adc: Set driver data before enabling runtime PM

When stress-testing the system by repeatedly unbinding and binding the ADC device in a loop, and the ADC is a supplier for another device (e.g., a thermal hardware block that reads temperature through the ADC), it may happen that the ADC device is runtime-resumed immediately after runtime PM is enabled, triggered by its consumer. At this point, since drvdata is not yet set and the driver's runtime PM callbacks rely on it, a crash can occur. To avoid this, set drvdata just after it was allocated.

Affected products

6
  • Linux/Kernelcpe-rescue5 versions
    6.14+ 4 more
    • (no CPE)range: 6.14
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.14,<6.16.4
    • cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*
    • (no CPE)
  • osv-coords
    Range: >= 6.14.0, < 6.16.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.