PT-2025-40082 · Mlx5E+3 · Mlx5E+3

Published

2025-10-01

·

Updated

2026-04-20

·

CVE-2025-39908

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to hardware timestamping (hwtstamp) within network device operations. Specifically, the issue involves failing to properly acquire the operations lock in lower paths during hwtstamp callbacks. This inconsistency can lead to potential problems when invoking ndo (net device operations) functions. Kernel logs indicate warnings related to netdev update features and functions like mlx5 hwtstamp set and mlx5e hwtstamp set. The issue is associated with a patch converting legacy ioctl calls to ndo hwtstamp get/set, and is not present in the mainline kernel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2025-39908

Affected Products

Astra Linux
Linux Kernel
Mlx5
Mlx5E