PT-2025-42251 · Linux · Linux Kernel

Published

2025-09-18

·

Updated

2025-10-16

·

CVE-2025-39976

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists within the Linux kernel related to the futex hash allocate default() function. Specifically, the copy process() function utilizes an incorrect error exit path following a failure within futex hash allocate default(). This results in improper lock handling, where locks (tasklist lock and siglock) are unlocked in the wrong sequence, potentially leading to instability or unexpected behavior. The correct exit label, bad fork cancel cgroup, should be used instead of the current exit path. The sched cgroup fork() function does not allocate resources requiring freeing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03756
CVE-2025-39976

Affected Products

Linux Kernel