CVE-2025-39848: ax25: properly unshare skbs in ax25_kiss_rcv()
ax25: properly unshare skbs in ax25kissrcv()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel ax25 subsystemto a version that resolves this vulnerability.Patch 7aaed57c5c28 - Upgrade
Upgrade
Linux kernel net subsystemto a version that resolves this vulnerability.Patch c353e8983e0d
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39848?
CVE-2025-39848 is classified as a medium severity vulnerability affecting the Linux kernel.
How do I fix CVE-2025-39848?
To resolve CVE-2025-39848, update your Linux kernel to the latest version where this issue has been patched.
What is the impact of CVE-2025-39848?
The impact of CVE-2025-39848 can lead to a system crash due to a NULL pointer dereference in the ax25_kiss_rcv() function.
Who reported the CVE-2025-39848 vulnerability?
CVE-2025-39848 was reported by security researcher Bernard Pidoux.
Which components are affected by CVE-2025-39848?
CVE-2025-39848 primarily affects the ax25 networking protocol implementation in the Linux kernel.