In the Linux kernel, the following vulnerability has been resolved:
drm: bridge: anx7625: Fix NULL pointer dereference with early IRQ
If the interrupt occurs before resource initialization is complete, the interrupt handler/worker may access uninitialized data such as the I2C tcpc_client device, potentially leading to NULL pointer dereference.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39934.json"
}[
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"247016465604652714813689272729251734631",
"267887356794604186521693086605387916808",
"267042106438561763723106108469543145891",
"169703499240056150675564923267523407337",
"82415956793303520814958234797215954663",
"183575800585786591587873815931770838505",
"192168905877090623162493964895204748390",
"336551843358328165010569362074647584948",
"227884825059497639180557370513357338022"
]
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-39934-1afb016a",
"target": {
"file": "drivers/gpu/drm/bridge/analogix/anx7625.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1a7ea294d57fb61485d11b3f2241d631d73025cb"
},
{
"signature_version": "v1",
"digest": {
"length": 3015.0,
"function_hash": "203544097135064431573318552320632482476"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-39934-76c703c0",
"target": {
"function": "anx7625_i2c_probe",
"file": "drivers/gpu/drm/bridge/analogix/anx7625.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1a7ea294d57fb61485d11b3f2241d631d73025cb"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39934.json"