cbcvebase.
CVE-2025-39955
published 2025-10-09

CVE-2025-39955: In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). syzbot reported the splat below…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). syzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk in the TCP_ESTABLISHED state. [0] syzbot reused the server-side TCP Fast Open socket as a new client before the TFO socket completes 3WHS: 1. accept() 2. connect(AF_UNSPEC) 3. connect() to another destination As of accept(), sk->sk_state is TCP_SYN_RECV, and tcp_disconnect() changes it to TCP_CLOSE and makes connect() possible, which restarts timers. Since tcp_disconnect() forgot to clear tcp_sk(sk)->fastopen_rsk, the retransmit timer triggered the warning and the intended packet was not retransmitted. Let's call reqsk_fastopen_remove() in tcp_disconnect(). [0]: WARNING: CPU: 2 PID: 0 at net/ipv4/tcp_timer.c:542 tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7)) Modules linked in: CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.17.0-rc5-g201825fb4278 #62 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7)) Code: 41 55 41 54 55 53 48 8b af b8 08 00 00 48 89 fb 48 85 ed 0f 84 55 01 00 00 0f b6 47 12 3c 03 74 0c 0f b6 47 12 3c 04 74 04 90 0b 90 48 8b 85 c0 00 00 00 48 89 ef 48 8b 40 30 e8 6a 4f 06 3e RSP: 0018:ffffc900002f8d40 EFLAGS: 00010293 RAX: 0000000000000002 RBX: ffff888106911400 RCX: 0000000000000017 RDX: 0000000002517619 RSI: ffffffff83764080 RDI: ffff888106911400 RBP: ffff888106d5c000 R08: 0000000000000001 R09: ffffc900002f8de8 R10: 00000000000000c2 R11: ffffc900002f8ff8 R12: ffff888106911540 R13: ffff888106911480 R14: ffff888106911840 R15: ffffc900002f8de0 FS: 0000000000000000(0000) GS:ffff88907b768000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f8044d69d90 CR3: 0000000002c30003 CR4: 0000000000370ef0 Call Trace: tcp_write_timer (net/ipv4/tcp_timer.c:738) cal

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 8336886f786fdacbc19b719c1f7ea91eb70706d4 < 7ec092a91ff351dcde89c23e795b73a328274db67ec092a91ff351dcde89c23e795b73a328274db6
linuxlinux>= 8336886f786fdacbc19b719c1f7ea91eb70706d4 < a4378dedd6e07e62f2fccb17d78c9665718763d0a4378dedd6e07e62f2fccb17d78c9665718763d0
linuxlinux>= 8336886f786fdacbc19b719c1f7ea91eb70706d4 < 33a4fdf0b4a25f8ce65380c3b0136b407ca5760933a4fdf0b4a25f8ce65380c3b0136b407ca57609
linuxlinux>= 8336886f786fdacbc19b719c1f7ea91eb70706d4 < 17d699727577814198d744d6afe54735c6b54c9917d699727577814198d744d6afe54735c6b54c99
linuxlinux>= 8336886f786fdacbc19b719c1f7ea91eb70706d4 < dfd06131107e7b699ef1e2a24ed2f7d17c917753dfd06131107e7b699ef1e2a24ed2f7d17c917753
linuxlinux>= 8336886f786fdacbc19b719c1f7ea91eb70706d4 < fa4749c065644af4db496b338452a69a3e5147d9fa4749c065644af4db496b338452a69a3e5147d9
linuxlinux>= 8336886f786fdacbc19b719c1f7ea91eb70706d4 < ae313d14b45eca7a6bb29cb9bf396d977e7d28fbae313d14b45eca7a6bb29cb9bf396d977e7d28fb
linuxlinux>= 8336886f786fdacbc19b719c1f7ea91eb70706d4 < 45c8a6cc2bcd780e634a6ba8e46bffbdf1fc5c0145c8a6cc2bcd780e634a6ba8e46bffbdf1fc5c01
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.9-16.16.9-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 3.7 < 5.4.3005.4.300
linuxlinux_kernel>= 5.11 < 5.15.1945.15.194

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.