| Name | CVE-2025-39836 | 
| Description | In the Linux kernel, the following vulnerability has been resolved:  efi: stmm: Fix incorrect buffer allocation method  The communication buffer allocated by setup_mm_hdr() is later on passed to tee_shm_register_kernel_buf(). The latter expects those buffers to be contiguous pages, but setup_mm_hdr() just uses kmalloc(). That can cause various corruptions or BUGs, specifically since commit 9aec2fb0fd5e ("slab: allocate frozen pages"), though it was broken before as well.  Fix this by using alloc_pages_exact() instead of kmalloc(). | 
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
| References | DSA-6008-1 | 
The table below lists information on source packages.
The information below is based on the following data on fixed versions.