Answer in brief
CVE-2025-39817 records a Unknown severity vulnerability in efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=da27a24383b2b10bf6ebd0db29b325548aafecb4 <0f63fbabeaaaaaaf5b742a2f4c1b4590d50bf1f6 || >=da27a24383b2b10bf6ebd0db29b325548aafecb4 <794399019301944fd6d2e0d7a51b3327e26c410e || >=da27a24383b2b10bf6ebd0db29b325548aafecb4 <568e7761279b99c6daa3002290fd6d8047ddb6d2 || >=da27a24383b2b10bf6ebd0db29b325548aafecb4 <d7f5e35e70507d10cbaff5f9e194ed54c4ee14f7 || >=da27a24383b2b10bf6ebd0db29b325548aafecb4 <925599eba46045930b850a98ae594d2e3028ac40 || >=da27a24383b2b10bf6ebd0db29b325548aafecb4 <c2925cd6207079c3f4d040d082515db78d63afbf || >=da27a24383b2b10bf6ebd0db29b325548aafecb4 <71581a82f38e5a4d807d71fc1bb59aead80ccf95 || >=da27a24383b2b10bf6ebd0db29b325548aafecb4 <a6358f8cf64850f3f27857b8ed8c1b08cfc4685c || 688289c4b745c018b3449b4b4c5a2030083c8eaf || >=3.8.2 <3.9 | 0f63fbabeaaaaaaf5b742a2f4c1b4590d50bf1f6, 794399019301944fd6d2e0d7a51b3327e26c410e, 568e7761279b99c6daa3002290fd6d8047ddb6d2, d7f5e35e70507d10cbaff5f9e194ed54c4ee14f7, 925599eba46045930b850a98ae594d2e3028ac40, c2925cd6207079c3f4d040d082515db78d63afbf, 71581a82f38e5a4d807d71fc1bb59aead80ccf95, a6358f8cf64850f3f27857b8ed8c1b08cfc4685c, 3.9 |
| Linux/Linuxgeneric | 3.9 | Not reported |
| Siemens/SIMATIC CN 4100generic | >=0 <V5.0 | V5.0 |
Published upstream
Sep 16, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare Observed on kernel 6.6 (present on master as well): BUG: KASAN: slab-out-of-bounds in memcmp+0x98/0xd0 Call trace: kasan_check_range+0xe8/0x190 __asan_loadN+0x1c/0x28 memcmp+0x98/0xd0 efivarfs_d_compare+0x68/0xd8 __d_lookup_rcu_op_compare+0x178/0x218 __d_lookup_rcu+0x1f8/0x228 d_alloc_parallel+0x150/0x648 lookup_open.isra.0+0x5f0/0x8d0 open_last_lookups+0x264/0x828 path_openat+0x130/0x3f8 do_filp_open+0x114/0x248 do_sys_openat2+0x340/0x3c0 __arm64_sys_openat+0x120/0x1a0 If dentry->d_name.len < EFI_VARIABLE_GUID_LEN , 'guid' can become negative, leadings to oob. The issue can be triggered by parallel lookups using invalid filename: T1 T2 lookup_open ->lookup simple_lookup d_add // invalid dentry is added to hash list lookup_open d_alloc_parallel __d_lookup_rcu __d_lookup_rcu_op_compare hlist_bl_for_each_entry_rcu // invalid dentry can be retrieved ->d_compare efivarfs_d_compare // oob Fix it by checking 'guid' before cmp.
Quoted source text, attributed separately from HOL analysis.