In the Linux kernel, the following vulnerability has been resolved:
hsr: hold rcu and dev lock for hsr_get_port_ndev
hsr_get_port_ndev calls hsr_for_each_port, which need to hold rcu lock.
On the other hand, before return the port device, we need to hold the
device reference to avoid UaF in the caller function.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Tue, 23 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linux
Linux linux Kernel |
|
Vendors & Products |
Linux
Linux linux Kernel |
Tue, 23 Sep 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Linux kernel, the following vulnerability has been resolved: hsr: hold rcu and dev lock for hsr_get_port_ndev hsr_get_port_ndev calls hsr_for_each_port, which need to hold rcu lock. On the other hand, before return the port device, we need to hold the device reference to avoid UaF in the caller function. | |
Title | hsr: hold rcu and dev lock for hsr_get_port_ndev | |
References |
|

Status: PUBLISHED
Assigner: Linux
Published:
Updated: 2025-09-29T06:01:29.027Z
Reserved: 2025-04-16T07:20:57.144Z
Link: CVE-2025-39872

No data.

Status : Awaiting Analysis
Published: 2025-09-23T06:15:46.533
Modified: 2025-09-24T18:11:24.520
Link: CVE-2025-39872


Updated: 2025-09-23T16:03:15Z