CVE-2025-39846

Source
https://cve.org/CVERecord?id=CVE-2025-39846
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39846.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39846
Downstream
Related
Published
2025-09-19T15:26:19.932Z
Modified
2026-05-07T04:16:17.582568Z
Summary
pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()
Details

In the Linux kernel, the following vulnerability has been resolved:

pcmcia: Fix a NULL pointer dereference in _iodynfindioregion()

In _iodynfindioregion(), pcmciamakeresource() is assigned to res and used in pcibusallocresource(). There is a dereference of res in pcibusallocresource(), which could lead to a NULL pointer dereference on failure of pcmciamakeresource().

Fix this bug by adding a check of res.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39846.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
49b1153adfe18a3cce7e70aa26c690f275917cd0
Fixed
b990c8c6ff50649ad3352507398e443b1e3527b2
Fixed
5ff2826c998370bf7f9ae26fe802140d220e3510
Fixed
4bd570f494124608a0696da070f00236a96fb610
Fixed
ce3b7766276894d2fbb07e2047a171f9deb965de
Fixed
2ee32c4c4f636e474cd8ab7c19a68cf36072ea93
Fixed
fafa7450075f41d232bc785a4ebcbf16374f2076
Fixed
d7286005e8fde0a430dc180a9f46c088c7d74483
Fixed
44822df89e8f3386871d9cad563ece8e2fd8f0e7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39846.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.35
Fixed
5.4.299
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.243
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.192
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.151
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.105
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.46
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.16.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39846.json"