Resource management error in Linux kernel clk samsung driver



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2025-39728
CWE-ID CWE-399
Exploitation vector Local
Public exploit N/A
Vulnerable software
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Resource management error

EUVDB-ID: #VU107773

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-39728

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the samsung_clk_init() function in drivers/clk/samsung/clk.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions

CPE2.3 External links

https://git.kernel.org/stable/c/00307934eb94aaa0a99addfb37b9fe206f945004
https://git.kernel.org/stable/c/0fef48f4a70e45a93e73c39023c3a6ea624714d6
https://git.kernel.org/stable/c/157de9e48007a20c65d02fc0229a16f38134a72d
https://git.kernel.org/stable/c/24307866e0ac0a5ddb462e766ceda5e27a6fbbe3
https://git.kernel.org/stable/c/4d29a6dcb51e346595a15b49693eeb728925ca43
https://git.kernel.org/stable/c/a1500b98cd81a32fdfb9bc63c33bb9f0c2a0a1bf
https://git.kernel.org/stable/c/d19d7345a7bcdb083b65568a11b11adffe0687af
https://git.kernel.org/stable/c/d974e177369c034984cece9d7d4fada9f8b9c740


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###