PT-2025-37245 · Google+7 · Gs101+7

CVE-2025-39788

·

Published

2025-07-07

·

Updated

2026-08-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A flaw exists in the Linux kernel related to the SCSI UFS Exynos driver. Specifically, the programming of HCI UTRL NEXUS TYPE was incorrect on Google gs101 devices due to an integer shift exceeding the bit width, resulting in undefined behavior and a UBSAN shift-out-of-bounds warning in drivers/ufs/host/ufs-exynos.c:1113:21. The issue stemmed from shifting a value by more than the width of the int type. The fix involves using the BIT() macro to ensure correct type casting and proper value writing to UTRL NEXUS TYPE. The same change was applied to nutmrs and UTMRL NEXUS TYPE.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15692
CVE-2025-39788
DLA-4327-1
DLA-4328-1
DSA-6008-1
DSA-6009-1
ECHO-F8E0-779F-07FD
OESA-2026-2580
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:4393-1
SUSE-SU-2025:4422-1
SUSE-SU-2025:4505-1
SUSE-SU-2025:4516-1
SUSE-SU-2025:4517-1
SUSE-SU-2025:4521-1
SUSE-SU-2026:20039-1
SUSE-SU-2026:20059-1
SUSE-SU-2026:20473-1
SUSE-SU-2026:20496-1
SUSE-SU-2026:20560-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Exynos
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu
Gs101