Junglewise Threat Intelligence

CVE-2025-39826: Linux Kernel use-after-free in ROSE networking protocol

CVE-2025-39826 · Severity: high · CVSS 7 · Published 2025-09-16

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's ROSE networking protocol, which is used for amateur radio packet switching. A flaw in how the system tracks active connections can allow a local user to trigger a system crash or potentially execute unauthorized code. This could lead to a complete loss of system availability or the compromise of sensitive data on affected industrial and computing devices.

Technical details

A use-after-free vulnerability exists in the net/rose subsystem of the Linux kernel due to non-atomic reference counting in the 'use' field of struct rose_neigh. A race condition can occur during ioctl operations (specifically rose_rt_ioctl) where the reference count reaches zero and the structure is freed while its timer is still active or other code paths still hold a pointer. This allows a local attacker with low privileges to trigger a kernel panic or achieve arbitrary code execution. The fix involves converting the 'use' field to refcount_t to ensure atomic increments and decrements via rose_neigh_hold() and rose_neigh_put().

Affected products

  • Linux Linux Kernel 2.6.12-rc2 to 6.11.y
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2025-08-23: patched: Initial patch submitted by Takamitsu Iwai
  • 2025-09-16: disclosed: CVE-2025-39826 published

References

Related threats