CVE-2025-39992 — Missing Synchronization in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 92.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
mm: swap: check for stable address space before operating on the VMA
It is possible to hit a zero entry while traversing the vmas in unuse_mm()
called from swapoff path and accessing it causes the OOPS:
Unable to handle kernel NULL pointer dereference at virtual address
0000000000000446--> Loading the memory from offset 0x40 on the
XA_ZERO_ENTRY as address.
Mem abort info:
ESR = 0x0000000096000005
EC = 0x25: DABT (current EL)…
Affected Packages5 packages
▶CVEListV5linux/linuxd2406291483775ecddaee929231a39c70c08fda2 — 4e5f060d7347466f77aaff1c0d5a6c4f1fb217ac+4