cbcvebase.
CVE-2025-39977
published 2025-10-15

CVE-2025-39977: In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI syzbot managed to trigger the following…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.8th percentile
In the Linux kernel, the following vulnerability has been resolved:

futex: Prevent use-after-free during requeue-PI

syzbot managed to trigger the following race:

T1 T2

futex_wait_requeue_pi()
futex_do_wait()
schedule()
futex_requeue()
futex_proxy_trylock_atomic()
futex_requeue_pi_prepare()
requeue_pi_wake_futex()
futex_requeue_pi_complete()
/* preempt */

* timeout/ signal wakes T1 *

futex_requeue_pi_wakeup_sync() // Q_REQUEUE_PI_LOCKED
futex_hash_put()
// back to userland, on stack futex_q is garbage

/* back */
wake_up_state(q->task, TASK_NORMAL);

In this scenario futex_wait_requeue_pi() is able to leave without using
futex_q::lock_ptr for synchronization.

This can be prevented by reading futex_q::task before updating the
futex_q::requeue_state. A reference on the task_struct is not needed
because requeue_pi_wake_futex() is invoked with a spinlock_t held which
implies a RCU read section.

Even if T1 terminates immediately after, the task_struct will remain valid
during T2's wake_up_state(). A READ_ONCE on futex_q::task before
futex_requeue_pi_complete() is enough because it ensures that the variable
is read before the state is updated.

Read futex_q::task before updating the requeue state, use it for the
following wakeup.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < cb5d19a61274b51b49601214a87af573b43d60facb5d19a61274b51b49601214a87af573b43d60fa
linuxlinux>= 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 348736955ed6ca6e99ca24b93b1d3fbfe352c181348736955ed6ca6e99ca24b93b1d3fbfe352c181
linuxlinux>= 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < a170b9c0dde83312b8b58ccc91509c7c15711641a170b9c0dde83312b8b58ccc91509c7c15711641
linuxlinux>= 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < d824b2dbdcfe3c390278dd9652ea526168ef6850d824b2dbdcfe3c390278dd9652ea526168ef6850
linuxlinux>= 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < b549113738e8c751b613118032a724b772aa83f2b549113738e8c751b613118032a724b772aa83f2
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 5.15.0 < 6.1.1556.1.155
linuxlinux_kernel>= 6.13.0 < 6.16.106.16.10
linuxlinux_kernel>= 6.2.0 < 6.6.1096.6.109
linuxlinux_kernel>= 6.7.0 < 6.12.506.12.50
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.