CVE-2025-39925Improper Update of Reference Count in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1
Latest updateOct 14

Description

In the Linux kernel, the following vulnerability has been resolved: can: j1939: implement NETDEV_UNREGISTER notification handler syzbot is reporting unregister_netdevice: waiting for vcan0 to become free. Usage count = 2 problem, for j1939 protocol did not have NETDEV_UNREGISTER notification handler for undoing changes made by j1939_sk_bind(). Commit 25fe97cb7620 ("can: j1939: move j1939_priv_put() into sk_destruct callback") expects that a call to j1939_priv_put() can be unconditionally de

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

NVDlinux/linux_kernel5.46.16.8+1
Debianlinux/linux_kernel< 6.16.8-1
CVEListV5linux/linux9d71dd0c70099914fcd063135da3c580865e924cda9e8f429139928570407e8f90559b5d46c20262+2
debiandebian/linux< linux 6.16.8-1 (forky)

Patches

🔴Vulnerability Details

2
OSV
CVE-2025-39925: In the Linux kernel, the following vulnerability has been resolved: can: j1939: implement NETDEV_UNREGISTER notification handler syzbot is reporting u2025-10-01
GHSA
GHSA-g35j-5v93-p28m: In the Linux kernel, the following vulnerability has been resolved: can: j1939: implement NETDEV_UNREGISTER notification handler syzbot is reporting2025-10-01

📋Vendor Advisories

4
Microsoft
can: j1939: implement NETDEV_UNREGISTER notification handler2025-10-14
Red Hat
kernel: can: j1939: implement NETDEV_UNREGISTER notification handler2025-10-01
Debian
CVE-2025-39925: linux - In the Linux kernel, the following vulnerability has been resolved: can: j1939:...2025
Microsoft
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file2021-11-09

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws2025-10-14
CVE-2025-39925 — Improper Update of Reference Count | cvebase