Executive brief
A vulnerability was identified in the Linux kernel's OcteonTX2 network driver that could lead to a system crash or instability. The issue occurs when the system attempts to use memory that has already been marked for deletion during network traffic flow configuration. This could potentially be exploited to cause a denial-of-service condition on affected systems, including certain industrial controllers from Siemens that utilize this kernel code.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's Marvell OcteonTX2 NIC driver (octeontx2-pf) within the otx2_tc_add_flow() function. The root cause is a race condition where kfree_rcu() is called to schedule the freeing of 'new_node', but the pointer is subsequently dereferenced in a region that is not RCU-safe (specifically, while holding a mutex). An attacker with the ability to manipulate TC (Traffic Control) flower offloads could trigger this UAF, potentially leading to kernel memory corruption or a system crash. The fix involves re-ordering the code to ensure all dereferences of the node occur before the RCU free is queued. Patches have been released for various stable kernel branches including 6.1.y, 6.6.y, 6.12.y, and 6.16.y.
Affected products
- Linux Linux Kernel 5.14 to 6.17
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2025-09-23: disclosed: Initial patch submitted by Dan Carpenter
- 2025-10-15: advisory: CVE-2025-39978 published
References
- https://git.kernel.org/stable/c/5723120423a753a220b8b2954b273838b9d7e74a
- https://git.kernel.org/stable/c/a8a63f27c3a8a3714210d32b12fd0f16d0337414
- https://git.kernel.org/stable/c/c41b2941a024d4ec7c768e16ffb10a74b188fced
- https://git.kernel.org/stable/c/d9c70e93ec5988ab07ad2a92d9f9d12867f02c56
- https://git.kernel.org/stable/c/df2c071061ed52d2225d97b212d27ecedf456b8a
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html