CVE-2025-39799
Linux Ubuntu vulnerability analysis and mitigation

Overview

CVE-2025-39799 is a Linux kernel vulnerability in the ACPI processor performance library (acpi/processor/perflib) involving an incorrectly placed pr->performance check that can prevent the frequency QoS request from being added when a processor lacks a performance object. This flaw was introduced by commit d33bd88ac0eb and published on September 12, 2025. Note: This CVE has been marked as Rejected by its CVE Numbering Authority, meaning it was withdrawn after initial publication (Red Hat CVE, Microsoft MSRC). The Feedly-estimated CVSS v3.1 base score is 5.5 (Medium), reflecting a local, low-privilege attack vector with high availability impact (Red Hat CVE).

Technical details

The root cause is an improper placement of the pr->performance NULL check within the ACPI processor performance library. Commit d33bd88ac0eb ("ACPI: processor: perflib: Fix initial _PPC limit application") added a check that skips adding the frequency QoS request when a CPU has no ACPI performance object; however, this also prevents the QoS object from being registered at all for such CPUs. When the CPU is subsequently taken offline, freq_qos_remove_request() triggers a WARN() because the QoS request was never added. The fix moves the pr->performance check to occur before acpi_processor_get_platform_limit() is called, ensuring the QoS request is always registered alongside the CPU's cpufreq policy regardless of performance object presence (ENISA EUVD). This is classified as an improper resource management / logic error in the kernel's ACPI subsystem.

Impact

Successful triggering of this bug causes a kernel WARN() when a CPU without an ACPI performance object is taken offline, potentially disrupting CPU hotplug operations and frequency scaling. The availability impact is rated High, as it can destabilize CPU management on affected systems. There is no confidentiality or integrity impact; the scope is limited to the local system (ENISA EUVD, Red Hat CVE).

Exploitability

There is no known public proof-of-concept exploit, and no evidence of in-the-wild exploitation has been reported (ENISA EUVD). The EPSS score is approximately 0.033% (0.000330), indicating a very low probability of exploitation in the near term. This CVE has been rejected by its CNA and is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation would require local access with low privileges on a system with CPUs lacking ACPI performance objects (Red Hat CVE).

Mitigation and workarounds

Because this CVE has been officially rejected/withdrawn, no formal security advisory patch is required. However, the underlying kernel logic error was addressed via upstream Linux kernel commits targeting multiple stable branches (e.g., commits cb4b5f4a, fc36403e, edc065c1, fd9cad6b, 19849010, and others across stable series). Administrators running affected kernel versions — particularly Microsoft Azure Linux 3 kernel 6.6.96.2-2 — should update to a kernel version that includes these fixes (Microsoft MSRC, ENISA EUVD). Monitoring system logs for unexpected WARN() messages related to freq_qos_remove_request during CPU offline operations is also advisable.

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7867HIGH7.8
  • Linux Debian logoLinux Debian
  • udisks2-lsm
NoYesAug 06, 2026
CVE-2026-64604NONEN/A
  • Linux Debian logoLinux Debian
  • linux-azure-fips
NoYesAug 06, 2026
CVE-2026-64603NONEN/A
  • Linux Debian logoLinux Debian
  • linux-riscv-5.15
NoYesAug 06, 2026
CVE-2026-64602NONEN/A
  • Linux Debian logoLinux Debian
  • linux-azure-fde-6.17
NoYesAug 06, 2026
CVE-2026-64601NONEN/A
  • Linux Debian logoLinux Debian
  • linux-gcp
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management