Wind River Support Network

HomeDefectsLIN1025-5367
Acknowledged

LIN1025-5367 : Security Advisory - linux - CVE-2025-39978

Created: Oct 15, 2025    Updated: Oct 17, 2025
Found In Version: 10.25.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()[EOL][EOL]This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node"[EOL]and then dereferences it on the next line.  Two lines later, we take[EOL]a mutex so I don't think this is an RCU safe region.  Re-order it to do[EOL]the dereferences before queuing up the free.
Live chat
Online