PT-2025-38562 · Linux+1 · Linux Kernel+1

Published

2025-04-16

·

Updated

2025-09-19

·

CVE-2025-39855

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the ice ptp ts irq() function where it does not check if the timestamp tracker is initialized before its first access. This can lead to a NULL pointer dereference or use-after-free bug, potentially triggered by a race condition between a Tx timestamp interrupt and the driver reset logic. The issue is related to the "low latency" firmware interface for accessing and reading Tx timestamps on E810 devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-13451
CVE-2025-39855

Affected Products

Astra Linux
Linux Kernel