CVE-2025-39788 is a high-severity vulnerability in the Linux kernel's Universal Flash Storage (UFS) driver for Exynos chipsets, specifically affecting Debian and other Linux distributions. It stems from incorrect programming of the HCI_UTRL_NEXUS_TYPE due to an integer overflow during a bit shift operation, leading to undefined behavior. The vulnerability has a CVSS score of 7.8 (High), indicating that a local attacker with low privileges could achieve high confidentiality, integrity, and availability impacts with low attack complexity. There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. However, the CVE has garnered some community discussion and media coverage, suggesting awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.9, < 5.10.241CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.190CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.149CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.103CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026kernel: scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE
Sep 11, 2025scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE
Sep 9, 2025