cbcvebase.
CVE-2025-39951
published 2025-10-04

CVE-2025-39951: In the Linux kernel, the following vulnerability has been resolved: um: virtio_uml: Fix use-after-free after put_device in probe When register_virtio_device()…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.8th percentile
In the Linux kernel, the following vulnerability has been resolved: um: virtio_uml: Fix use-after-free after put_device in probe When register_virtio_device() fails in virtio_uml_probe(), the code sets vu_dev->registered = 1 even though the device was not successfully registered. This can lead to use-after-free or other issues.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 04e5b1fb01834a602acaae2276b67a783a8c6159 < 14c231959a16ca41bfdcaede72483362a8c645d714c231959a16ca41bfdcaede72483362a8c645d7
linuxlinux>= 04e5b1fb01834a602acaae2276b67a783a8c6159 < 5e94e44c9cb30d7a383d8ac227f24a8c9326b7705e94e44c9cb30d7a383d8ac227f24a8c9326b770
linuxlinux>= 04e5b1fb01834a602acaae2276b67a783a8c6159 < aaf900a83508c8cd5cdf765e7749f9076196ec7faaf900a83508c8cd5cdf765e7749f9076196ec7f
linuxlinux>= 04e5b1fb01834a602acaae2276b67a783a8c6159 < 4f364023ddcfe83f7073b973a9cb98584b7f2a464f364023ddcfe83f7073b973a9cb98584b7f2a46
linuxlinux>= 04e5b1fb01834a602acaae2276b67a783a8c6159 < 00e98b5a69034b251bb36dc6e7123d7648e218e400e98b5a69034b251bb36dc6e7123d7648e218e4
linuxlinux>= 04e5b1fb01834a602acaae2276b67a783a8c6159 < c2ff91255e0157b356cff115d8dc3eeb5162edf2c2ff91255e0157b356cff115d8dc3eeb5162edf2
linuxlinux>= 04e5b1fb01834a602acaae2276b67a783a8c6159 < 7ebf70cf181651fe3f2e44e95e7e5073d594c9c07ebf70cf181651fe3f2e44e95e7e5073d594c9c0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.9-16.16.9-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 5.11 < 5.15.1945.15.194
linuxlinux_kernel>= 5.16 < 6.1.1546.1.154
linuxlinux_kernel>= 5.5 < 5.10.2455.10.245
linuxlinux_kernel>= 6.13 < 6.16.96.16.9
linuxlinux_kernel>= 6.2 < 6.6.1086.6.108
linuxlinux_kernel>= 6.7 < 6.12.496.12.49
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-azure-5.15

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.