Linux Kernel Vulnerability Affecting Phylink Mechanism and Locking Behavior
CVE-2025-39915
Currently unrated
What is CVE-2025-39915?
A vulnerability in the Linux kernel involves the phylink mechanism and the phy_config_inband function, where a locking dependency exists between &pl->state_mutex and &phy->lock. This could lead to a potential deadlock situation if concurrent calls to phylink functions are made. The problem arises from an inconsistency in the locking order, which can interfere with the normal operation of PHY state changes. It is recommended that the locking responsibility be adjusted to prevent these issues.
Affected Version(s)
Linux 5fd0f1a02e750e2db4038dee60edea669ce5aab1 < 052ac41c379c8b87629808be612a482b2d0ae283
Linux 5fd0f1a02e750e2db4038dee60edea669ce5aab1
Linux 6.14