CVE-2025-39872

Source
https://cve.org/CVERecord?id=CVE-2025-39872
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39872.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39872
Downstream
Published
2025-09-23T06:00:45.528Z
Modified
2026-05-15T11:53:25.476245478Z
Summary
hsr: hold rcu and dev lock for hsr_get_port_ndev
Details

In the Linux kernel, the following vulnerability has been resolved:

hsr: hold rcu and dev lock for hsrgetport_ndev

hsrgetportndev calls hsrforeachport, which need to hold rcu lock. On the other hand, before return the port device, we need to hold the device reference to avoid UaF in the caller function.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39872.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.12.64
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.16.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39872.json"