PT-2025-37245 · Google+7 · Gs101+7
CVE-2025-39788
·
Published
2025-07-07
·
Updated
2026-08-30
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A flaw exists in the Linux kernel related to the SCSI UFS Exynos driver. Specifically, the programming of
HCI UTRL NEXUS TYPE was incorrect on Google gs101 devices due to an integer shift exceeding the bit width, resulting in undefined behavior and a UBSAN shift-out-of-bounds warning in drivers/ufs/host/ufs-exynos.c:1113:21. The issue stemmed from shifting a value by more than the width of the int type. The fix involves using the BIT() macro to ensure correct type casting and proper value writing to UTRL NEXUS TYPE. The same change was applied to nutmrs and UTMRL NEXUS TYPE.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Memory Corruption
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Exynos
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu
Gs101