PT-2025-38548 · Linux+9 · Linux Kernel+9

Published

2025-09-19

·

Updated

2026-05-26

·

CVE-2025-39841

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a use-after-free issue in the SCSI Low-Level Fibre Channel (lpfc) driver. A buffer release sequence error in the deferred receive path could lead to a double-free or use-after-free condition. The issue occurs because the RQ buffer was freed before the context pointer was cleared under lock, potentially allowing concurrent paths to access the released memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:18281
ALSA-2025:18318
ALSA-2025:19102
ALSA-2025:19103
AZL-67538
AZL-74829
BDU:2025-14116
CESA-2025_19102
CESA-2025_19103
CVE-2025-39841
DLA-4327-1
DLA-4328-1
DSA-6008-1
DSA-6009-1
ECHO-81F7-1A9E-000A
INFESA-2025_0006
INFSA-2025_18281
INFSA-2025_19102
INFSA-2025_19103
INFSA-2025_21112
OESA-2026-2416
OESA-2026-2417
OESA-2026-2418
OPENSUSE-SU-2025:20081-1
RHSA-2025:18281
RHSA-2025:18318
RHSA-2025:19102
RHSA-2025:19103
RHSA-2025:21083
RHSA-2025:21112
RHSA-2025:21118
RHSA-2025:22661
RHSA-2025:22995
RHSA-2025:22996
RHSA-2025_18281
RHSA-2025_19102
RHSA-2025_19103
RHSA-2025_21112
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4189-1
SUSE-SU-2025:4301-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Almalinux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu
Lpfc