U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CVE-2025-39823 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that come from guest min and dest_id are guest-controlled indices. Using array_index_nospec() after the bounds checks clamps these values to mitigate speculative execution side-channels.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NIST CVSS score
NIST: NVD
N/A
NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
https://git.kernel.org/stable/c/31a0ad2f60cb4816e06218b63e695eb72ce74974 kernel.org
https://git.kernel.org/stable/c/33e974c2d5a82b2f9d9ba0ad9cbaabc1c8e3985f kernel.org
https://git.kernel.org/stable/c/67a05679621b7f721bdba37a5d18665d3aceb695 kernel.org
https://git.kernel.org/stable/c/72777fc31aa7ab2ce00f44bfa3929c6eabbeaf48 kernel.org
https://git.kernel.org/stable/c/c87bd4dd43a624109c3cc42d843138378a7f4548 kernel.org
https://git.kernel.org/stable/c/d51e381beed5e2f50f85f49f6c90e023754efa12 kernel.org
https://git.kernel.org/stable/c/f49161646e03d107ce81a99c6ca5da682fe5fb69 kernel.org
https://git.kernel.org/stable/c/f57a4bd8d6cb5af05b8ac1be9098e249034639fb kernel.org

Weakness Enumeration

CWE-ID CWE Name Source

Change History

1 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2025-39823
NVD Published Date:
09/16/2025
NVD Last Modified:
09/16/2025
Source:
kernel.org