
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39848 is a vulnerability discovered in the Linux kernel affecting the ax25kissrcv() function. The issue was identified on September 19, 2025, when Bernard Pidoux reported a regression caused by commit c353e8983e0d ("net: introduce per netns packet chains"). The vulnerability stems from the ax25kissrcv() function's failure to verify whether input skb is shared before queuing or mangling it (NVD).
The vulnerability manifests when skb->dev becomes NULL, leading to a crash in _netifreceiveskbcore(). Prior to the commit that introduced this regression, various bugs or corruptions could occur without causing a major system crash. This issue is similar to a previous vulnerability that was fixed with commit 7aaed57c5c28 ("phonet: properly unshare skbs in phonet_rcv()") (NVD).
The vulnerability can lead to system crashes and potential memory corruptions in the Linux kernel's network stack, specifically in the AX.25 protocol implementation (NVD).
The vulnerability has been addressed in various Linux distributions. Debian has included fixes for this vulnerability in version 6.12.48-1 for the stable distribution (trixie) and version 6.1.153-1 for the oldstable distribution (bookworm). Users are recommended to upgrade their Linux packages to the latest versions (Debian Security, Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."