Junglewise Threat Intelligence

CVE-2025-39872: Linux Kernel use-after-free in hsr_get_port_ndev

CVE-2025-39872 · Severity: high · CVSS 7.8 · Published 2025-09-23

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability has been identified in the Linux kernel's High-availability Seamless Redundancy (HSR) networking component. This component is used to ensure network reliability in industrial and critical infrastructure environments. An exploit could allow a local user to cause a system crash or potentially gain unauthorized access to sensitive data by triggering a memory error during network port management.

Technical details

A use-after-free (UaF) vulnerability exists in the Linux kernel's HSR implementation. The function 'hsr_get_port_ndev' failed to properly hold the RCU (Read-Copy-Update) lock while iterating through ports using 'hsr_for_each_port'. Additionally, it did not increment the device reference count before returning the port device to the caller. This oversight allows the underlying device object to be freed while still in use by the caller, leading to memory corruption or system instability. The vulnerability is reachable by local users and has been addressed by adding proper RCU locking and 'dev_hold'/'dev_put' calls in the HSR and TI ICSSG driver code. Patches are available in stable kernel branches including 6.12.64 and 6.16.8.

Affected products

  • Linux Linux Kernel 6.12.63 through 6.12.64, 6.14 through 6.16.8

Timeline

  • 2025-09-05: disclosed: Initial patch submitted by Hangbin Liu
  • 2025-09-23: advisory: NVD published CVE-2025-39872
  • 2026-01-08: patched: Final stable fix committed to kernel.org stable tree

References

Related threats