CVE-2025-39999
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39999 affects the Linux kernel and involves a double free vulnerability in the block multiqueue (blk-mq) subsystem. The vulnerability was discovered and disclosed on October 15, 2025, specifically related to the handling of tags when the nr_requests queue attribute is modified (NVD).

Technical details

The vulnerability occurs when users trigger tags growth through the queue sysfs attribute nr_requests. When this happens, hctx->sched_tags is freed directly and replaced with newly allocated tags during the blk_mq_tag_update_depth() operation. The issue arises because hctx->sched_tags is derived from elevator->et->tags, while et->tags still references the freed tags. This leads to a double free condition when the elevator exits, resulting in a kernel panic (NVD).

Impact

When exploited, this vulnerability can cause a kernel panic, leading to system crashes and potential denial of service conditions. The issue affects the block layer functionality of the Linux kernel, which is critical for storage operations (NVD).

Mitigation and workarounds

The fix involves replacing et->tags with newly allocated tags alongside the hctx->sched_tags replacement. However, it's noted that there are some long-term problems that will require additional refactoring to be fixed thoroughly (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-oem-6.14
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-core
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • linux-aws-fips
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management