CVE-2025-39695Out-of-bounds Read in Linux

CWE-125Out-of-bounds Read6 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 5

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Flush delayed SKBs while releasing RXE resources When skb packets are sent out, these skb packets still depends on the rxe resources, for example, QP, sk, when these packets are destroyed. If these rxe resources are released when the skb packets are destroyed, the call traces will appear. To avoid skb packets hang too long time in some network devices, a timestamp is added when these skb packets are created. If the

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel6.106.12.44+2
Debianlinux/linux_kernel< 6.12.48-1+1
CVEListV5linux/linux1a633bdc8fd9e9e4a9f9a668ae122edfc5aacc86732d4bd7b78a2752ad43cc39287ef41893c5eee2+3
debiandebian/linux< linux 6.16.5-1 (forky)

Patches

🔴Vulnerability Details

2
OSV
CVE-2025-39695: In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Flush delayed SKBs while releasing RXE resources When skb packets are se2025-09-05
GHSA
GHSA-r8x7-576r-pcrg: In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Flush delayed SKBs while releasing RXE resources When skb packets are2025-09-05

📋Vendor Advisories

3
Red Hat
kernel: RDMA/rxe: Flush delayed SKBs while releasing RXE resources2025-09-05
Debian
CVE-2025-39695: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: F...2025
Microsoft
Exiv2 has an out-of-bounds read in AsfVideo::streamProperties2024-07-09
CVE-2025-39695 — Out-of-bounds Read in Linux | cvebase