Executive brief
A vulnerability exists in the Linux kernel's ROSE networking protocol, which is used for amateur radio packet switching. A flaw in how the system tracks active connections can allow a local user to trigger a system crash or potentially execute unauthorized code. This could lead to a complete loss of system availability or the compromise of sensitive data on affected industrial and computing devices.
Technical details
A use-after-free vulnerability exists in the net/rose subsystem of the Linux kernel due to non-atomic reference counting in the 'use' field of struct rose_neigh. A race condition can occur during ioctl operations (specifically rose_rt_ioctl) where the reference count reaches zero and the structure is freed while its timer is still active or other code paths still hold a pointer. This allows a local attacker with low privileges to trigger a kernel panic or achieve arbitrary code execution. The fix involves converting the 'use' field to refcount_t to ensure atomic increments and decrements via rose_neigh_hold() and rose_neigh_put().
Affected products
- Linux Linux Kernel 2.6.12-rc2 to 6.11.y
- Siemens SIMATIC CN 4100 < V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2025-08-23: patched: Initial patch submitted by Takamitsu Iwai
- 2025-09-16: disclosed: CVE-2025-39826 published
References
- https://git.kernel.org/stable/c/0085b250fcc79f900c82a69980ec2f3e1871823b
- https://git.kernel.org/stable/c/203e4f42596ede31498744018716a3db6dbb7f51
- https://git.kernel.org/stable/c/d860d1faa6b2ce3becfdb8b0c2b048ad31800061
- https://git.kernel.org/stable/c/f8c29fc437d03a98fb075c31c5be761cc8326284
- https://git.kernel.org/stable/c/fb07156cc0742ba4e93dfcc84280c011d05b301f
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html