PT-2025-40069 · Linux+5 · Linux Kernel+5
Published
2025-09-09
·
Updated
2026-05-07
·
CVE-2025-39895
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.17.0-rc4-dirty #343
Description
The Linux kernel contained a flaw in the
sched numa find nth cpu() function. This function, when used with an offline CPU mask, could lead to a null pointer dereference due to an incorrect bsearch result. This issue occurred when all CPUs in the specified mask were offline, causing a kernel panic. The issue was triggered on an rk3399 (LLLLbb) system when booting with all big CPUs offline, resulting in an internal error and ultimately a kernel panic.Recommendations
Update to version 6.17.0-rc4-dirty #343 or a later version to address this issue.
Exploit
Fix
NULL Pointer Dereference
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu
Rk3399