CVE-2025-39897 | Linux Kernel up to 6.12.45/6.16.5 net dmaengine_desc_get_metadata_ptr buffer overflow (Nessus ID 269661 / WID-SEC-2025-2170)
A vulnerability was found in Linux Kernel up to 6.12.45/6.16.5. It has been declared as critical. This vulnerability affects the function dmaengine_desc_get_metadata_ptr of the component net. The manipulation results in buffer overflow.
This vulnerability is reported as CVE-2025-39897. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.