CVE-2025-39855
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's ice driver (CVE-2025-39855) was discovered and disclosed on September 19, 2025. The issue affects the E810 device's low latency firmware interface for accessing and reading Tx timestamps, specifically in the ice_ptp_ts_irq() function's handling of the tracker initialization check (NVD).

Technical details

The vulnerability stems from the ice_ptp_ts_irq() function not verifying if the tracker is initialized before its first access. This oversight can result in NULL dereference or use-after-free bugs when a Tx timestamp interrupt races with the driver reset logic. The issue has been assigned a CVSS 3.1 score of 5.7 (AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H), indicating moderate severity with local access required (RedHat).

Impact

When exploited, the vulnerability can cause kernel NULL pointer dereference, potentially leading to system crashes or denial of service conditions. The bug manifests as a NULL dereference with address 0x0000000000000000, affecting the _find_first_bit and ice_misc_intr functions (NVD).

Mitigation and workarounds

The fix involves modifying the code to check if the tracker is marked as initialized before accessing the in_use bitmap and other fields. The reset flow has been updated to clear the init field under lock before tearing down the tracker, preventing any use-after-free or NULL access issues (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-core
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • rv
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management