Junglewise Threat Intelligence

CVE-2025-39698: Linux Kernel use-after-free in io_uring futex wait

CVE-2025-39698 · Severity: high · CVSS 7.8 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's io_uring subsystem, which is used for high-performance input/output operations. A flaw in how the system handles synchronization primitives (futexes) could allow a local user with limited access to crash the system or gain full administrative control. This issue has been resolved in recent kernel updates.

Technical details

A use-after-free (UAF) vulnerability exists in io_uring/futex.c due to improper state management in io_futex_wait(). The vulnerability stems from a mismatch where io_futex_data is assigned to the io_kiocb async_data field without immediately setting the REQ_F_ASYNC_DATA flag. Furthermore, during failure cleanup, the handler frees the data but fails to nullify the async_data pointer. A local attacker can exploit this inconsistent state to trigger a use-after-free, potentially leading to arbitrary code execution in kernel context or local privilege escalation. Patches have been released for stable kernel branches (e.g., 6.12.44, 6.16.4).

Affected products

  • Linux Linux Kernel 6.7 to 6.12.43, 6.13 to 6.16.3

Timeline

  • 2025-08-21: disclosed: Vulnerability reported to vendor by Trend Micro ZDI
  • 2025-08-21: patched: Initial fix committed by Jens Axboe
  • 2025-09-05: advisory: CVE-2025-39698 published
  • 2025-09-24: other: Coordinated public release of ZDI advisory

References

Related threats