FlawAtlas
Search the atlas
CVE-2025-39965 Not scored

xfrm: xfrm_alloc_spi shouldn't use 0 as SPI

In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create states and add them to the byspi list with this value. __xfrm_state_delete doesn't remove those states from the byspi list, since they shouldn't be there, and this shows up as a UAF the next time we go through the byspi list.

Exploit probability 0.2%
Published October 13, 2025
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Linux Kernel
Unknown Unknown

898 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2025:20091-1
related SUSE-SU-2025:21040-1
related SUSE-SU-2025:21052-1
related SUSE-SU-2025:21056-1
related SUSE-SU-2025:21064-1
related SUSE-SU-2025:21080-1
related SUSE-SU-2025:21147-1
related SUSE-SU-2025:21180-1
related SUSE-SU-2025:4057-1
related SUSE-SU-2025:4111-1
related SUSE-SU-2025:4128-1
related SUSE-SU-2025:4132-1
related SUSE-SU-2025:4139-1
related SUSE-SU-2025:4140-1
related SUSE-SU-2025:4141-1
related SUSE-SU-2025:4149-1
related SUSE-SU-2025:4301-1
related SUSE-SU-2025:4320-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-39965

In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create states and add them to the byspi list with this value. __xfrm_state_delete doesn't remove those states from the byspi list, since they shouldn't be there, and this shows up as a UAF the next time we go through the byspi list.

View original source

05 / REFERENCES

Further evidence