CVE-2025-39965: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create states and add them to the byspi list with this value. __xfrm_state_delete doesn't remove those states from the byspi list, since they shouldn't be there, and this shows up as a UAF the next time we go through the byspi list.

Affected products

  • Linux Linux Kernel: from 6.6.103, before 6.6.109 (fixed in 6.6.109); from 6.12.43, before 6.12.50 (fixed in 6.12.50); from 6.15.11, before 6.16 (fixed in 6.16); from 6.16.2, before 6.16.10 (fixed in 6.16.10); version 6.17 only

Published 2025-10-13. Last modified 2026-07-30.