cbcvebase.
CVE-2025-39832
published 2025-09-16

CVE-2025-39832: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix lockdep assertion on sync reset unload event Fix lockdep assertion triggered…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix lockdep assertion on sync reset unload event Fix lockdep assertion triggered during sync reset unload event. When the sync reset flow is initiated using the devlink reload fw_activate option, the PF already holds the devlink lock while handling unload event. In this case, delegate sync reset unload event handling back to the devlink callback process to avoid double-locking and resolve the lockdep warning. Kernel log: WARNING: CPU: 9 PID: 1578 at devl_assert_locked+0x31/0x40 [...] Call Trace: mlx5_unload_one_devl_locked+0x2c/0xc0 [mlx5_core] mlx5_sync_reset_unload_event+0xaf/0x2f0 [mlx5_core] process_one_work+0x222/0x640 worker_thread+0x199/0x350 kthread+0x10b/0x230 ? __pfx_worker_thread+0x10/0x10 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x8e/0x100 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.5-1 (forky)linux 6.16.5-1 (forky)
linuxlinux
linuxlinux>= 7a9770f1bfeaeddf5afabd3244e2c4c4966be37d < ddac9d0fe2493dd550cbfc75eeaf31e9b6dac959ddac9d0fe2493dd550cbfc75eeaf31e9b6dac959
linuxlinux>= 7a9770f1bfeaeddf5afabd3244e2c4c4966be37d < 0c87dba9ccd3801d3b503f0b4fd41be343af4f060c87dba9ccd3801d3b503f0b4fd41be343af4f06
linuxlinux>= 7a9770f1bfeaeddf5afabd3244e2c4c4966be37d < 06d897148e79638651800d851a69547b56b4be2e06d897148e79638651800d851a69547b56b4be2e
linuxlinux>= 7a9770f1bfeaeddf5afabd3244e2c4c4966be37d < 902a8bc23a24882200f57cadc270e15a2cfaf2bb902a8bc23a24882200f57cadc270e15a2cfaf2bb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.48-16.12.48-1
linuxlinux_kernel>= 0 < 6.16.5-16.16.5-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.13 < 6.16.56.16.5
linuxlinux_kernel>= 6.5 < 6.6.1046.6.104
linuxlinux_kernel>= 6.7 < 6.12.456.12.45
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.