Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-39939

24
FAUCET Score

CVE-2025-39939 is a memory corruption vulnerability affecting the Linux kernel, specifically within the s390 IOMMU subsystem when using an identity domain. This flaw, categorized as CWE-787, can lead to out-of-bounds access due to incorrect handling of counter information for identity domains, which lack the expected s390_domain structure. With a CVSS score of 7.8 (High), a local attacker with low privileges could exploit this to achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.15, < 6.16.9CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*
6.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*
6.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*
6.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
3.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 16th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2025-39939Moderate

kernel: iommu/s390: Fix memory corruption when using identity domain

Oct 4, 2025

References

git.kernel.org / stable/c/17a58caf3863163c4a84a218a9649be2c8061443
Patch
git.kernel.org / stable/c/b3506e9bcc777ed6af2ab631c86a9990ed97b474
Patch