LiveActive security incident?Get immediate response
CVE Record

CVE-2025-39907: mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer Avoid below overlapping mappings by using a contiguous non-cacheable buffer. [ 4.077708] DMA-API: stm32_fmc2_nfc 48810000.nand-controller: cacheline tracking EEXIST, overlapping mappings aren't supported [ 4.089103] WARNING: CPU: 1 PID: 44 at kernel/dma/debug.c:568 add_dma_entry+0x23c/0x300 [ 4.097071] Modules linked in: [ 4.100101] CPU: 1 PID: 44 Comm: kworker/u4:2 Not tainted 6.1.82 #1 [ 4.106346] Hardware name: STMicroelectronics STM32MP257F VALID1 SNOR / MB1704 (LPDDR4 Power discrete) + MB1703 + MB1708 (SNOR MB1730) (DT) [ 4.118824] Workqueue: events_unbound deferred_probe_work_func [ 4.124674] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 4.131624] pc : add_dma_entry+0x23c/0x300 [ 4.135658] lr : add_dma_entry+0x23c/0x300 [ 4.139792] sp : ffff800009dbb490 [ 4.143016] x29: ffff800009dbb4a0 x28: 0000000004008022 x27: ffff8000098a6000 [ 4.150174] x26: 0000000000000000 x25: ffff8000099e7000 x24: ffff8000099e7de8 [ 4.157231] x23: 00000000ffffffff x22: 0000000000000000 x21: ffff8000098a6a20 [ 4.164388] x20: ffff000080964180 x19: ffff800009819ba0 x18: 0000000000000006 [ 4.171545] x17: 6361727420656e69 x16: 6c6568636163203a x15: 72656c6c6f72746e [ 4.178602] x14: 6f632d646e616e2e x13: ffff800009832f58 x12: 00000000000004ec [ 4.185759] x11: 00000000000001a4 x10: ffff80000988af58 x9 : ffff800009832f58 [ 4.192916] x8 : 00000000ffffefff x7 : ffff80000988af58 x6 : 80000000fffff000 [ 4.199972] x5 : 000000000000bff4 x4 : 0000000000000000 x3 : 0000000000000000 [ 4.207128] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000812d2c40 [ 4.214185] Call trace: [ 4.216605] add_dma_entry+0x23c/0x300 [ 4.220338] debug_dma_map_sg+0x198/0x350 [ 4.224373] __dma_map_sg_attrs+0xa0/0x110 [ 4.228411] dma_map_sg_attrs+0x10/0x2c [ 4.232247] stm32_fmc2_nfc_xfer.isra.0+0x1c8/0x3fc [ 4.237088] stm32_fmc2_nfc_seq_read_page+0xc8/0x174 [ 4.242127] nand_read_oob+0x1d4/0x8e0 [ 4.245861] mtd_read_oob_std+0x58/0x84 [ 4.249596] mtd_read_oob+0x90/0x150 [ 4.253231] mtd_read+0x68/0xac

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel driver issue in the STM32 FMC2 raw NAND controller path. It can trigger overlapping DMA mappings for an ECC buffer, producing kernel DMA warnings during NAND reads. The provided sources do not show remote exploitation, privilege escalation, or confirmed active abuse.

Executive priority

Handle as targeted embedded Linux maintenance, not an internet-wide emergency. Prioritize affected STM32-based products because kernel storage-driver faults can affect reliability, but current sources do not justify emergency incident response.

Technical view

The resolved kernel change avoids overlapping mappings in mtd: rawnand: stm32_fmc2 by using a contiguous non-cacheable ECC buffer. The trace shows DMA-API cacheline tracking warnings during stm32_fmc2_nfc NAND read paths on STM32MP257 hardware. Severity, CVSS, and CWE are not provided.

Likely exposure

Exposure appears limited to Linux systems using the STM32 FMC2 NAND controller driver and affected kernel builds. General Linux servers without this hardware path are unlikely to be affected based on the supplied evidence.

Exploitation context

The bundle marks KEV as false and provides no public exploitation claim. The evidence is a kernel warning and stable-tree fix, not a demonstrated attack path. Treat exploitation status as unconfirmed.

Researcher notes

Key uncertainty is impact. The public record describes a resolved DMA mapping bug and warning trace, but not confidentiality, integrity, or availability consequences. Validate by hardware presence, kernel branch, and whether downstream vendors backported the stable commits.

Mitigation direction

  • Apply a vendor kernel update containing the referenced stable fixes.
  • Prioritize embedded or appliance fleets using STM32 FMC2 raw NAND.
  • Check Debian LTS and platform vendor advisories for packaged fixes.
  • If no update is available, ask the vendor for supported guidance.

Validation and detection

  • Inventory systems for STM32 FMC2 NAND controller usage.
  • Map running kernel builds against vendor advisories and referenced fixes.
  • Review boot or kernel logs for DMA-API overlapping mapping warnings.
  • Confirm patched kernels no longer emit the reported warning path.
Prepared
Confidence
medium
Sources
11

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-39907 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
1ADP providers
10Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux2cd457f328c100bc98e36d55fe210e9ab067c704, 2cd457f328c100bc98e36d55fe210e9ab067c704, 2cd457f328c100bc98e36d55fe210e9ab067c704, 2cd457f328c100bc98e36d55fe210e9ab067c704, 2cd457f328c100bc98e36d55fe210e9ab067c704, 2cd457f328c100bc98e36d55fe210e9ab067c704, 2cd457f328c100bc98e36d55fe210e9ab067c704, 2cd457f328c100bc98e36d55fe210e9ab067c704unaffected
LinuxLinux5.1, 0, 5.4.300, 5.10.245, 5.15.194, 6.1.153, 6.6.107, 6.12.48, 6.16.8, 6.17affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.