PT-2025-37977 · Linux+5 · Linux Kernel+5

Published

2025-08-25

·

Updated

2026-05-07

·

CVE-2025-39832

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A lockdep assertion issue was resolved in the net/mlx5 component of the Linux kernel. The issue occurred during a sync reset unload event when the PF already held the devlink lock while handling the unload event. The fix delegates sync reset unload event handling back to the devlink callback process to avoid double-locking and resolve the lockdep warning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Assertion Failure

Improper Locking

Weakness Enumeration

Related Identifiers

AZL-67407
BDU:2025-14983
CVE-2025-39832
DSA-6008-1
OESA-2025-2633
OESA-2025-2634
OESA-2025-2635
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu
Mlx5