Use After Free Vulnerability in Linux Kernel Affecting MLX5 Command
CVE-2025-39979
What is CVE-2025-39979?
A vulnerability exists in the MLX5 command of the Linux kernel, leading to a use after free condition during the release of flow counters. The issue stems from an improper initialization of the HWS action reference count and mutex in the function mlx5_cmd_hws_delete_fte(). If the counter structure has already been freed when a rule is deleted, it can cause kernel tracebacks, leading to potential instability. The vulnerability is addressed by ensuring proper initialization of these parameters to prevent accessing freed memory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Linux b581f4266928d3b5d1bbe711e39623d9a1696091 < 3c77f6d244188c3fb11f6aec40bbfe884f1803b5
Linux b581f4266928d3b5d1bbe711e39623d9a1696091 < 6043819e707cefb1c9e59d6e431dcfa735c4f975
Linux 6.14