CVE-2025-39768
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39768 is a vulnerability in the Linux kernel's net/mlx5 Hardware Steering (HWS) subsystem related to improper error handling during complex rules rehash operations. When moving rules between matchers fails, the flawed error flow can cause kernel soft lock-ups or other problematic behavior instead of allowing the kernel to continue functioning gracefully. It affects Linux kernel versions 6.16 through 6.16.3 (fixed in 6.16.4) and release candidates 6.17-rc1 and 6.17-rc2. It carries a CVSS v3.1 base score of 5.5 (Medium), requiring only local access with low privileges (Feedly).

Technical details

The root cause is classified as CWE-617 (Reachable Assertion), stemming from incorrect error-handling logic in the net/mlx5 HWS complex rules rehash code path. Specifically, four distinct flaws exist: polling for completion when rule creation failed before enqueueing; continuing to poll after a TIMEOUT (when no completion will arrive); aborting all remaining rule processing upon receiving any completion error; and overwriting the first meaningful error code with a generic one before returning to the caller. These issues collectively cause the kernel to enter soft lock-up states or exhibit undefined behavior when the rehash operation encounters errors. The fix consolidates all four corrections into a single patch to avoid leaving partially broken code (Feedly, Kernel Patch 1, Kernel Patch 2).

Impact

Successful exploitation can cause kernel soft lock-ups and denial of service on affected systems, as the broken error flow prevents the kernel from recovering gracefully from failed rule-migration operations. Network steering rules may be left in a broken state, potentially disrupting network traffic handling on systems using Mellanox/NVIDIA ConnectX hardware with Hardware Steering enabled. There is no confidentiality or integrity impact; the vulnerability is limited to availability (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability requires local access with low privileges to trigger, limiting its attack surface. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Mitigation and workarounds

The primary remediation is to update to Linux kernel version 6.16.4 or later, which includes the fix for this vulnerability. The patches are available in the upstream kernel stable tree (commits 37d54bc28d09 and 4a842b1bf18a). As a workaround where patching is not immediately possible, administrators should limit local user access to affected systems and monitor for unusual kernel behavior or network steering anomalies. Systems not using Mellanox/NVIDIA MLX5 hardware with Hardware Steering are not affected (Kernel Patch 1, Kernel Patch 2).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management