PT-2025-36283 · Linux+4 · Linux Kernel+4

Published

2025-01-01

·

Updated

2026-05-26

·

CVE-2025-39689

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in its ftrace functionality where the reader of filter files does not allocate and copy the hash, leading to a use-after-free (UAF) condition. Specifically, the reader of set ftrace filter and set ftrace notrace keeps a pointer to filter hashes without allocating a copy, unlike the writer. This can cause issues when the global tracer hashes are updated while locks are released. Allocating and copying the hash for reading filter files, similar to the writer, resolves the UAF bugs and simplifies the code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-66962
AZL-73707
BDU:2025-15194
CVE-2025-39689
DLA-4327-1
DLA-4328-1
DSA-6008-1
DSA-6009-1
ECHO-3E9C-3CBB-0CA6
MGASA-2025-0234
MGASA-2025-0235
OESA-2025-2268
OESA-2025-2269
OESA-2025-2270
OESA-2025-2271
OESA-2025-2272
OESA-2025-2273
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0447-1
SUSE-SU-2026:0471-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu