Improper Control of Dynamically-Managed Code Resources Affecting firmware-nonfree package, versions <20250410-1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-FIRMWARENONFREE-14038358
  • published17 Nov 2025
  • disclosed11 Nov 2025

Introduced: 11 Nov 2025

NewCVE-2025-26405  (opens in a new tab)
CWE-913  (opens in a new tab)

How to fix?

Upgrade Debian:13 firmware-nonfree to version 20250410-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream firmware-nonfree package and not the firmware-nonfree package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.