Junglewise Threat Intelligence

CVE-2025-39979: Linux Kernel mlx5 use-after-free in flow counter release

CVE-2025-39979 · Severity: high · CVSS 7.8 · Published 2025-10-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Mellanox network driver that could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system incorrectly manages memory for network flow counters, leading to a 'use-after-free' condition. This could impact the stability of servers using Mellanox network hardware and potentially compromise data integrity or availability.

Technical details

A use-after-free (UAF) vulnerability exists in the net/mlx5 driver within the Linux kernel's flow steering (fs) component. The flaw is located in mlx5_cmd_hws_delete_fte(), where Hardware Steering (HWS) actions for local flow counters are released without proper initialization of the reference count and mutex. This lack of synchronization allows the counter structure to be freed while still being referenced during rule deletion. An attacker with local access could exploit this race condition or improper reference counting to trigger a kernel panic or achieve arbitrary code execution. The fix introduces proper initialization and implements refcounting for the local flow counter struct via mlx5_fc_local_get and mlx5_fc_local_put.

Affected products

  • Linux Linux Kernel 6.14, 6.16.10, 6.17

Timeline

  • 2025-09-22: other: Patch authored
  • 2025-10-15: disclosed: CVE published

References

Related threats