Junglewise Threat Intelligence

CVE-2025-39689: Linux Kernel use-after-free in ftrace filter file reading

CVE-2025-39689 · Severity: high · CVSS 7.8 · Published 2025-09-05

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel, Linux. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's ftrace component, which is used for analyzing system performance and behavior. A local attacker could exploit this flaw to cause a system crash or potentially gain unauthorized access to sensitive information. This issue affects various industrial control systems and embedded devices that rely on the Linux kernel.

Technical details

A use-after-free (UAF) vulnerability exists in kernel/trace/ftrace.c due to improper handling of filter hashes during read operations of 'set_ftrace_filter' and 'set_ftrace_notrace'. While write operations correctly allocate a copy of the hash, read operations previously maintained a pointer to the global tracer hash. Because this pointer remains static across function calls that release locks, the global hash can be updated or freed while the reader still holds the reference. An attacker with local access can trigger this race condition to achieve a use-after-free state. Patches have been released for multiple stable kernel branches to ensure readers also allocate and copy the hash.

Affected products

  • Linux Linux kernel/trace/ftrace.c
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5

Timeline

  • 2025-08-22: other: Patch authored
  • 2025-09-05: advisory: Initial publication date

References

Related threats