INFSA-2025:22405: kernel security update
Information about definition
Identificator: INFSA-2025:22405
Type: security
Release date: 2025-12-07 23:23:31 UTC
Information about package
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Vulnerabilities description
- CVE-2025-39864
A use-after-free issue was discovered in the cfg80211 subsystem, caused by freeing beacon_ies structures even when they were still referenced through hidden_beacon_bss.
- CVE-2025-39955
tcp_disconnect() failed to clear tcp_sk(sk)->fastopen_rsk when reusing a TFO socket (e.g., after accept() → connect(AF_UNSPEC) → connect() sequence). This left a stale reference, allowing the retransmit timer to access a freed request_sock, triggering a kernel warning or potential UAF.
- CVE-2025-38724
A vulnerability has been identified in the Linux kernel's Network File System (NFS) daemon that could allow for a Denial of Service and in worst case scenario Arbitrary Code Execution. This Use-After-Free flaw arises from a race condition when the kernel handles the confirmation of an NFS client identifier. If an NFS client is expiring while this confirmation is in progress, the system can attempt to use memory that is no longer allocated.
- CVE-2025-39898
n the Linux kernel, the following vulnerability has been resolved: e1000e: fix heap overflow in e1000_set_eeprom.
- CVE-2025-39918
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix linked list corruption.
- CVE-2025-39981
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix possible UAFs.
- CVE-2025-40058
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Disallow dirty tracking if incoherent page walk.
- CVE-2025-40185
In the Linux kernel, the following vulnerability has been resolved: ice: ice_adapter: release xa entry on adapter allocation failure.
Severity level
| CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
|---|---|---|---|
|
NIST — CVE-2025-38724
|
no information | 7.0 | no information |
|
NIST — CVE-2025-39864
|
no information | 7.0 | no information |
|
NIST — CVE-2025-39898
|
no information | 7.6 | no information |
|
NIST — CVE-2025-39918
|
no information | 7.6 | no information |
|
NIST — CVE-2025-39955
|
no information | 7.6 | no information |
|
NIST — CVE-2025-39981
|
no information | 7.3 | no information |
|
NIST — CVE-2025-40058
|
no information | 5.3 | no information |
|
NIST — CVE-2025-40185
|
no information | 4.4 | no information |
Updated packages