Executive brief
A vulnerability in the Linux kernel's networking component could allow a local attacker to cause a system crash or potentially execute unauthorized actions. The issue occurs when the system fails to properly manage memory during specific network data processing tasks (TCP BPF). This could lead to system instability or a denial-of-service condition, impacting the availability of the affected server.
Technical details
A vulnerability exists in net/ipv4/tcp_bpf.c where the kernel fails to properly handle memory allocation failures for psock->cork. When a BPF program uses bpf_msg_cork_bytes and subsequent memory allocation for the corking structure fails (e.g., due to fault injection or memory pressure), the kernel does not revert changes made to sk->sk_forward_alloc. This leads to an inconsistent socket state and a kernel splat in inet_sock_destruct. An attacker with local access could trigger this condition to cause a denial of service (system crash). The fix ensures sk_msg_free() is called and the 'copied' byte count is reset upon allocation failure.
Affected products
- Linux Linux Kernel 4.17 to 5.4.300, 5.5 to 5.10.245, 5.11 to 5.15.194, 5.16 to 6.1.153, 6.2 to 6.6.107, 6.7 to 6.12.48, 6.13 to 6.16.8
Timeline
- 2025-09-09: patched: Initial patch submitted by Kuniyuki Iwashima
- 2025-10-01: advisory: CVE-2025-39913 published
References
- https://git.kernel.org/stable/c/05366527f44cf4b884f3d9462ae8009be9665856
- https://git.kernel.org/stable/c/08f58d10f5abf11d297cc910754922498c921f91
- https://git.kernel.org/stable/c/539920180c55f5e13a2488a2339f94e6b8cb69e0
- https://git.kernel.org/stable/c/66bcb04a441fbf15d66834b7e3eefb313dd750c8
- https://git.kernel.org/stable/c/7429b8b9bfbc276fd304fbaebc405f46b421fedf
- https://git.kernel.org/stable/c/9c2a6456bdf9794474460d885c359b6c4522d6e3
- https://git.kernel.org/stable/c/a3967baad4d533dc254c31e0d221e51c8d223d58