
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39768 is a vulnerability in the Linux kernel's net/mlx5 Hardware Steering (HWS) subsystem related to improper error handling during complex rules rehash operations. When moving rules between matchers fails, the flawed error flow can cause kernel soft lock-ups or other problematic behavior instead of allowing the kernel to continue functioning gracefully. It affects Linux kernel versions 6.16 through 6.16.3 (fixed in 6.16.4) and release candidates 6.17-rc1 and 6.17-rc2. It carries a CVSS v3.1 base score of 5.5 (Medium), requiring only local access with low privileges (Feedly).
The root cause is classified as CWE-617 (Reachable Assertion), stemming from incorrect error-handling logic in the net/mlx5 HWS complex rules rehash code path. Specifically, four distinct flaws exist: polling for completion when rule creation failed before enqueueing; continuing to poll after a TIMEOUT (when no completion will arrive); aborting all remaining rule processing upon receiving any completion error; and overwriting the first meaningful error code with a generic one before returning to the caller. These issues collectively cause the kernel to enter soft lock-up states or exhibit undefined behavior when the rehash operation encounters errors. The fix consolidates all four corrections into a single patch to avoid leaving partially broken code (Feedly, Kernel Patch 1, Kernel Patch 2).
Successful exploitation can cause kernel soft lock-ups and denial of service on affected systems, as the broken error flow prevents the kernel from recovering gracefully from failed rule-migration operations. Network steering rules may be left in a broken state, potentially disrupting network traffic handling on systems using Mellanox/NVIDIA ConnectX hardware with Hardware Steering enabled. There is no confidentiality or integrity impact; the vulnerability is limited to availability (Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability requires local access with low privileges to trigger, limiting its attack surface. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
The primary remediation is to update to Linux kernel version 6.16.4 or later, which includes the fix for this vulnerability. The patches are available in the upstream kernel stable tree (commits 37d54bc28d09 and 4a842b1bf18a). As a workaround where patching is not immediately possible, administrators should limit local user access to affected systems and monitor for unusual kernel behavior or network steering anomalies. Systems not using Mellanox/NVIDIA MLX5 hardware with Hardware Steering are not affected (Kernel Patch 1, Kernel Patch 2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."