PT-2025-42266 · Linux+3 · Linux Kernel+3

Published

2025-09-28

·

Updated

2026-05-07

·

CVE-2025-39992

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to memory management and swap operations. Specifically, a race condition between fork() and swapoff can lead to a kernel NULL pointer dereference when traversing virtual memory areas (VMAs) during the unuse mm() process, triggered by the swapoff operation. This occurs when a process is forked, and a signal is sent to the parent process before the VMA duplication is complete, resulting in a partially valid memory tree being exposed. The issue arises when attempting to operate on a zero entry within the VMA list. The problem is addressed by ensuring a stable address space before operating on the VMA.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-02709
CVE-2025-39992
OESA-2025-2765
OESA-2025-2766
OESA-2025-2767
OPENSUSE-SU-2025:15671-1
OPENSUSE-SU-2025:20091-1
OPENSUSE-SU-2026:10301-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Linuxmint
Linux Kernel
Suse
Ubuntu