Junglewise Threat Intelligence

CVE-2025-39848: Linux Kernel memory corruption in ax25_kiss_rcv

CVE-2025-39848 · Severity: high · CVSS 8.8 · Published 2025-09-19

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's AX.25 network protocol implementation, which is used for amateur radio communications. An attacker on the same local network could send specially crafted data packets to cause a system crash or potentially corrupt memory. This could lead to a complete loss of system availability or unauthorized access to sensitive information.

Technical details

A vulnerability exists in the ax25_kiss_rcv() function within the Linux kernel's AX.25 network stack. The root cause is a failure to properly unshare socket buffers (skbs) before they are queued or mangled. When a shared skb is modified, it can lead to a NULL pointer dereference in __netif_receive_skb_core() or other memory corruption. An attacker within the same adjacent network (Layer 2) can exploit this to cause a Denial of Service (kernel panic) or potentially achieve remote code execution. The issue has been addressed by adding an skb_share_check() call in the affected receive path.

Affected products

  • Linux Linux Kernel 2.6.12 through 6.11.y
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-09-02: patched: Initial patch authored by Eric Dumazet
  • 2025-09-19: disclosed: CVE published

References

Related threats