{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-39826","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T07:20:57.140Z","datePublished":"2025-09-16T13:00:24.618Z","dateUpdated":"2026-08-05T12:05:28.135Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:05:28.135Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rose: convert 'use' field to refcount_t\n\nThe 'use' field in struct rose_neigh is used as a reference counter but\nlacks atomicity. This can lead to race conditions where a rose_neigh\nstructure is freed while still being referenced by other code paths.\n\nFor example, when rose_neigh->use becomes zero during an ioctl operation\nvia rose_rt_ioctl(), the structure may be removed while its timer is\nstill active, potentially causing use-after-free issues.\n\nThis patch changes the type of 'use' from unsigned short to refcount_t and\nupdates all code paths to use rose_neigh_hold() and rose_neigh_put() which\noperate reference counts atomically."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The `use` counter is manipulated from `rose_route_frame()` and `rose_rx_call_request()`, which process ROSE frames received from unauthenticated AX.25 peers on the same radio link or LAN segment (AX.25 also rides Ethernet via ETH_P_BPQ/bpqether). This is link-layer, not internet-routable, so Adjacent rather than Network.\nAC:L - The attacker controls both sides of the race by flooding CALL_REQUEST/CLEAR_REQUEST frames that concurrently drive locked increments in softirq and unlocked decrements in `rose_timer_expiry()`/`rose_kill_by_neigh()`, and the `rose_get_neigh()` window in `rose_connect()` is wide (includes a GFP_KERNEL allocation). Per guidance, races the attacker creates and UAFs are Low.\nPR:N - ROSE/AX.25 provides no authentication, so a peer injecting frames on the segment needs no credentials to reach `rose_route_frame()`/`rose_rx_call_request()` and drive the non-atomic counter. The CAP_NET_ADMIN route ioctls are the admin/victim side of the race, not a privilege the attacker must hold.\nUI:N - Exploitation requires only received frames and ordinary ROSE connection churn on a system with ROSE routing configured; no action by any local user is needed.\nS:U - The corruption is confined to kernel heap objects within the same security authority; there is no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - The use-after-free lets the attacker reclaim the freed `rose_neigh` with controlled data and have the kernel read it back through socket, route, timer and skb-queue references, enabling kernel memory disclosure.\nI:H - Stale `rose->neighbour`, `rose_route->neigh1/neigh2` and `rose_neigh_put()` on the freed object give arbitrary write and double-free primitives, and the embedded `timer_list` function pointers make control-flow hijack plausible.\nA:H - The freed `rose_neigh` still has armed `ftimer`/`t0timer` and live pointers from sockets and routes, so the UAF reliably produces kernel oops/panic and can be re-triggered at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/rose.h","net/rose/af_rose.c","net/rose/rose_in.c","net/rose/rose_route.c","net/rose/rose_timer.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fb07156cc0742ba4e93dfcc84280c011d05b301f","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f8c29fc437d03a98fb075c31c5be761cc8326284","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0085b250fcc79f900c82a69980ec2f3e1871823b","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"203e4f42596ede31498744018716a3db6dbb7f51","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d860d1faa6b2ce3becfdb8b0c2b048ad31800061","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/rose.h","net/rose/af_rose.c","net/rose/rose_in.c","net/rose/rose_route.c","net/rose/rose_timer.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"6.1.150","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.104","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.45","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.16.5","lessThanOrEqual":"6.16.*","status":"unaffected","versionType":"semver"},{"version":"6.17","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.150"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.104"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.45"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.16.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.17"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/fb07156cc0742ba4e93dfcc84280c011d05b301f"},{"url":"https://git.kernel.org/stable/c/f8c29fc437d03a98fb075c31c5be761cc8326284"},{"url":"https://git.kernel.org/stable/c/0085b250fcc79f900c82a69980ec2f3e1871823b"},{"url":"https://git.kernel.org/stable/c/203e4f42596ede31498744018716a3db6dbb7f51"},{"url":"https://git.kernel.org/stable/c/d860d1faa6b2ce3becfdb8b0c2b048ad31800061"}],"title":"net: rose: convert 'use' field to refcount_t","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T17:43:47.184Z"}},{"x_adpType":"supplier","providerMetadata":{"orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP","dateUpdated":"2026-07-14T12:42:58.519Z"},"affected":[{"vendor":"Siemens","product":"SIMATIC CN 4100","versions":[{"status":"affected","version":"0","lessThan":"V5.0","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"}],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"}]}]}}