CVE-2025-39990: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: bpf: Check the helper function is valid in get_helper_proto kernel test robot reported verifier bug [1] where the helper func pointer could be NULL due to disabled config option. As Alexei suggested we could check on that in get_helper_proto directly. Marking tail_call helper func with BPF_PTR_POISON, because it is unused by design. [1] https://lore.kernel.org/oe-lkp/202507160818.68358831-lkp@intel.com

Affected products

  • Linux Linux: from 5.8, before 6.12.50 (fixed in 6.12.50); from 6.13, before 6.16.10 (fixed in 6.16.10)

Published 2025-10-15. Last modified 2026-07-30.