CVE-2025-39675 Affecting kernel-uek-debug-modules package, versions <0:6.12.0-105.51.5.el9uek


Severity

Recommended
high

Based on Oracle Linux security rating.

Threat Intelligence

EPSS
0.04% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ORACLE9-KERNELUEKDEBUGMODULES-13868866
  • published10 Nov 2025
  • disclosed5 Sept 2025

Introduced: 5 Sep 2025

CVE-2025-39675  (opens in a new tab)

How to fix?

Upgrade Oracle:9 kernel-uek-debug-modules to version 0:6.12.0-105.51.5.el9uek or higher.
This issue was patched in ELSA-2025-25754.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel-uek-debug-modules package and not the kernel-uek-debug-modules package as distributed by Oracle. See How to fix? for Oracle:9 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session()

The function mod_hdcp_hdcp1_create_session() calls the function get_first_active_display(), but does not check its return value. The return value is a null pointer if the display list is empty. This will lead to a null pointer dereference.

Add a null pointer check for get_first_active_display() and return MOD_HDCP_STATUS_DISPLAY_NOT_FOUND if the function return null.

This is similar to the commit c3e9826a2202 ("drm/amd/display: Add null pointer check for get_first_active_display()").

(cherry picked from commit 5e43eb3cd731649c4f8b9134f857be62a416c893)

CVSS Base Scores

version 3.1