CVE-2025-39978 — Expired Pointer Dereference in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 87.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()
This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node"
and then dereferences it on the next line. Two lines later, we take
a mutex so I don't think this is an RCU safe region. Re-order it to do
the dereferences before queuing up the free.
Affected Packages7 packages
▶CVEListV5linux/linux68fbff68dbea35f9e6f7649dd22fce492a5aedac — 5723120423a753a220b8b2954b273838b9d7e74a+5