PT-2025-40069 · Linux+5 · Linux Kernel+5

Published

2025-09-09

·

Updated

2026-05-07

·

CVE-2025-39895

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc4-dirty #343
Description The Linux kernel contained a flaw in the sched numa find nth cpu() function. This function, when used with an offline CPU mask, could lead to a null pointer dereference due to an incorrect bsearch result. This issue occurred when all CPUs in the specified mask were offline, causing a kernel panic. The issue was triggered on an rk3399 (LLLLbb) system when booting with all big CPUs offline, resulting in an internal error and ultimately a kernel panic.
Recommendations Update to version 6.17.0-rc4-dirty #343 or a later version to address this issue.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Weakness Enumeration

Related Identifiers

AZL-68004
BDU:2025-15673
CVE-2025-39895
OESA-2025-2465
OESA-2025-2466
OESA-2025-2467
OPENSUSE-SU-2025:20091-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu
Rk3399