{"schema_version":"1.9.0","id":"CVE-2025-39846","published":"2025-09-19T15:26:19.932Z","modified":"2026-08-12T03:51:29.748530026Z","related":["SUSE-SU-2025:03600-1","SUSE-SU-2025:03634-1","SUSE-SU-2025:20851-1","SUSE-SU-2025:20861-1","SUSE-SU-2025:20870-1","SUSE-SU-2025:20898-1","SUSE-SU-2025:3751-1","SUSE-SU-2025:4057-1","SUSE-SU-2025:4132-1","SUSE-SU-2025:4141-1"],"summary":"pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\npcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()\n\nIn __iodyn_find_io_region(), pcmcia_make_resource() is assigned to\nres and used in pci_bus_alloc_resource(). There is a dereference of res\nin pci_bus_alloc_resource(), which could lead to a NULL pointer\ndereference on failure of pcmcia_make_resource().\n\nFix this bug by adding a check of res.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"49b1153adfe18a3cce7e70aa26c690f275917cd0"},{"fixed":"b990c8c6ff50649ad3352507398e443b1e3527b2"},{"fixed":"5ff2826c998370bf7f9ae26fe802140d220e3510"},{"fixed":"4bd570f494124608a0696da070f00236a96fb610"},{"fixed":"ce3b7766276894d2fbb07e2047a171f9deb965de"},{"fixed":"2ee32c4c4f636e474cd8ab7c19a68cf36072ea93"},{"fixed":"fafa7450075f41d232bc785a4ebcbf16374f2076"},{"fixed":"d7286005e8fde0a430dc180a9f46c088c7d74483"},{"fixed":"44822df89e8f3386871d9cad563ece8e2fd8f0e7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39846.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.35"},{"fixed":"5.4.299"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.243"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.192"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.151"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.105"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.46"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.16.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39846.json"}}],"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-089022.html"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2ee32c4c4f636e474cd8ab7c19a68cf36072ea93"},{"type":"WEB","url":"https://git.kernel.org/stable/c/44822df89e8f3386871d9cad563ece8e2fd8f0e7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4bd570f494124608a0696da070f00236a96fb610"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5ff2826c998370bf7f9ae26fe802140d220e3510"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b990c8c6ff50649ad3352507398e443b1e3527b2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ce3b7766276894d2fbb07e2047a171f9deb965de"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d7286005e8fde0a430dc180a9f46c088c7d74483"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fafa7450075f41d232bc785a4ebcbf16374f2076"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39846.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-39846"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39846.json"}}