CVE-2025-39936: crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked()
In the Linux kernel, the following vulnerability has been resolved:
crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked()
When
9770b428b1a2 ("crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown")
moved the error messages dumping so that they don't need to be issued by
the callers, it missed the case where __sev_firmware_shutdown() calls
__sev_platform_shutdown_locked() with a NULL argument which leads to
a NULL ptr deref on the shutdown path, during suspend to disk:
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: Oops: 0000 [#1] SMP NOPTI
CPU: 0 UID: 0 PID: 983 Comm: hib.sh Not tainted 6.17.0-rc4+ #1 PREEMPT(voluntary)
Hardware name: Supermicro Super Server/H12SSL-i, BIOS 2.5 09/08/2022
RIP: 0010:__sev_platform_shutdown_locked.cold+0x0/0x21 [ccp]
That rIP is:
00000000000006fd <__sev_platform_shutdown_locked.cold>:
6fd: 8b 13 mov (%rbx),%edx
6ff: 48 8b 7d 00 mov 0x0(%rbp),%rdi
703: 89 c1 mov %eax,%ecx
Code: 74 05 31 ff 41 89 3f 49 8b 3e 89 ea 48 c7 c6 a0 8e 54 a0 41 bf 92 ff ff ff e8 e5 2e 09 e1 c6 05 2a d4 38 00 01 e9 26 af ff ff <8b> 13 48 8b 7d 00 89 c1 48 c7 c6 18 90 54 a0 89 44 24 04 e8 c1 2e
RSP: 0018:ffffc90005467d00 EFLAGS: 00010282
RAX: 00000000ffffff92 RBX: 0000000000000000 RCX: 0000000000000000
^^^^^^^^^^^^^^^^
and %rbx is nice and clean.
Call Trace:
<TASK>
__sev_firmware_shutdown.isra.0
sev_dev_destroy
psp_dev_destroy
sp_destroy
pci_device_shutdown
device_shutdown
kernel_power_off
hibernate.cold
state_store
kernfs_fop_write_iter
vfs_write
ksys_write
do_syscall_64
entry_SYSCALL_64_after_hwframe
Pass in a pointer to the function-local error var in the caller.
With that addressed, suspending the ccp shows the error properly at
least:
ccp 0000:47:00.1: sev command 0x2 timed out, disabling PSP
ccp 0000:47:00.1: SEV: failed to SHUTDOWN error 0x0, rc -110
SEV-SNP: Leaking PFN range 0x146800-0x146a00
SEV-SNP: PFN 0x146800 unassigned, dumping non-zero entries in 2M PFN region: [0x146800 - 0x146a00]
...
ccp 0000:47:00.1: SEV-SNP firmware shutdown failed, rc -16, error 0x0
ACPI: PM: Preparing to enter system sleep state S5
kvm: exiting hardware virtualization
reboot: Power down
Btw, this driver is crying to be cleaned up to pass in a proper I/O
struct which can be used to store information between the different
functions, otherwise stuff like that will happen in the future again.
Security readout for executives and security teams
Plain-English summary
A Linux kernel bug can crash an affected system while it is hibernating or shutting down. The failure occurs in AMD Secure Encrypted Virtualization handling and primarily threatens availability. The supplied sources do not establish data theft, remote compromise, or a severity score.
Executive priority
Prioritize through normal kernel maintenance, with faster action for affected AMD SEV or SEV-SNP systems that use hibernation or have experienced shutdown crashes. Urgency cannot be rated definitively because no CVSS score or exploitation evidence is supplied.
Technical view
The CCP driver’s SEV firmware shutdown path passed NULL to __sev_platform_shutdown_locked(). Error-reporting changes later dereferenced that pointer, causing a kernel NULL-pointer fault during suspend-to-disk shutdown. The cited Linux stable commits correct the caller by passing a pointer to its local error variable.
Likely exposure
Potential exposure is limited to listed affected Linux kernel versions, including 6.16 through 6.16.9 and 6.17, when the relevant AMD CCP/PSP SEV or SEV-SNP shutdown path is exercised. The bundle does not provide distribution-specific package mappings or confirm exposure on systems without this hardware path.
Exploitation context
The CVE is not listed as KEV, and no supplied source reports active exploitation. Evidence demonstrates a reproducible kernel crash during hibernation or power-off processing. The bundle provides no evidence that the issue is remotely reachable or enables code execution.
Researcher notes
The fault is an availability-oriented NULL dereference introduced around error-message handling. Three stable-tree references are supplied, suggesting fixes across maintained branches, but the bundle does not map each commit to exact releases. Affected-version data is somewhat ambiguous and should be reconciled with distribution advisories.
Mitigation direction
Install a vendor kernel containing the applicable cited Linux stable fix.
Confirm the distribution’s security advisory maps its kernel package to this CVE.
Until updated, avoid hibernation on confirmed affected SEV or SEV-SNP hosts where operationally feasible.
Follow vendor guidance for production-safe workarounds and restart requirements.
Validation and detection
Inventory kernel versions on AMD SEV or SEV-SNP capable hosts.
Verify whether the vendor kernel includes the applicable cited fix commit.
Review kernel logs for CCP, PSP, SEV shutdown failures, NULL dereferences, or Oops events.
Test hibernation and shutdown only in a controlled non-production environment after updating.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-39936 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
4Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Oct 4, 2025, 07:30 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.