CVE-2025-39965

Updated: 2025-12-24 11:34:21.649967

Description:

In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create states and add them to the byspi list with this value. __xfrm_state_delete doesn't remove those states from the byspi list, since they shouldn't be there, and this shows up as a UAF the next time we go through the byspi list.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Released CLSA-2026:1767864313 2026-01-08 16:16:54
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM In Rollout CLSA-2025:1766617167 2025-12-25 06:01:24
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Released CLSA-2025:1766599987 2025-12-25 14:33:31
RHEL 7 ELS kernel 3.10.0 5.5 MEDIUM Released CLSA-2025:1766600619 2025-12-25 14:33:09