Linux Kernel Vulnerability Affecting Phylink Mechanism and Locking Behavior
CVE-2025-39915

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
1 October 2025

What is CVE-2025-39915?

A vulnerability in the Linux kernel involves the phylink mechanism and the phy_config_inband function, where a locking dependency exists between &pl->state_mutex and &phy->lock. This could lead to a potential deadlock situation if concurrent calls to phylink functions are made. The problem arises from an inconsistency in the locking order, which can interfere with the normal operation of PHY state changes. It is recommended that the locking responsibility be adjusted to prevent these issues.

Affected Version(s)

Linux 5fd0f1a02e750e2db4038dee60edea669ce5aab1 < 052ac41c379c8b87629808be612a482b2d0ae283

Linux 5fd0f1a02e750e2db4038dee60edea669ce5aab1

Linux 6.14

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-39915 : Linux Kernel Vulnerability Affecting Phylink Mechanism and Locking Behavior