PT-2025-39130 · Linux+5 · Linux Kernel+5

Published

2025-08-22

·

Updated

2026-05-26

·

CVE-2025-39873

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the xilinx can module, specifically in the xcan write frame() function, leading to a use-after-free condition involving transmitted SKB (Socket Buffer) data. The can put echo skb() function acquires ownership of the SKB and may free it during or after its call. However, the xcan write frame() function continues to access the SKB after this point. The fix involves ensuring that can put echo skb() is called only after all operations on the SKB are completed. A previous attempt to address this issue did not fully resolve the problem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

AZL-67650
AZL-74930
BDU:2025-13892
CVE-2025-39873
DLA-4328-1
ECHO-3FAE-E7D5-B3B7
MGASA-2025-0309
MGASA-2025-0310
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Xilinx Can