CVE-2025-39848
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39848 is a vulnerability discovered in the Linux kernel affecting the ax25kissrcv() function. The issue was identified on September 19, 2025, when Bernard Pidoux reported a regression caused by commit c353e8983e0d ("net: introduce per netns packet chains"). The vulnerability stems from the ax25kissrcv() function's failure to verify whether input skb is shared before queuing or mangling it (NVD).

Technical details

The vulnerability manifests when skb->dev becomes NULL, leading to a crash in _netifreceiveskbcore(). Prior to the commit that introduced this regression, various bugs or corruptions could occur without causing a major system crash. This issue is similar to a previous vulnerability that was fixed with commit 7aaed57c5c28 ("phonet: properly unshare skbs in phonet_rcv()") (NVD).

Impact

The vulnerability can lead to system crashes and potential memory corruptions in the Linux kernel's network stack, specifically in the AX.25 protocol implementation (NVD).

Mitigation and workarounds

The vulnerability has been addressed in various Linux distributions. Debian has included fixes for this vulnerability in version 6.12.48-1 for the stable distribution (trixie) and version 6.1.153-1 for the oldstable distribution (bookworm). Users are recommended to upgrade their Linux packages to the latest versions (Debian Security, Debian Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-39886MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-internal
NoYesSep 23, 2025
CVE-2025-39889N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug-kvm
NoYesSep 24, 2025
CVE-2025-39888N/AN/A
  • Linux KernelLinux Kernel
  • linux-fips
NoYesSep 23, 2025
CVE-2025-39887N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt
NoYesSep 23, 2025
CVE-2025-39884N/AN/A
  • Linux KernelLinux Kernel
  • kernel-kdump
NoYesSep 23, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management