# CVE-2025-39826

## Summary

- **CVE ID:** CVE-2025-39826
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 16, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

net: rose: convert 'use' field to refcount_t

The 'use' field in struct rose_neigh is used as a reference counter but
lacks atomicity. This can lead to race conditions where a rose_neigh
structure is freed while still being referenced by other code paths.

For example, when rose_neigh->use becomes zero during an ioctl operation
via rose_rt_ioctl(), the structure may be removed while its timer is
still active, potentially causing use-after-free issues.

This patch changes the type of 'use' from unsigned short to refcount_t and
updates all code paths to use rose_neigh_hold() and rose_neigh_put() which
operate reference counts atomically.

## Affected Products

- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (2.6.12)
- Linux — Linux (0)
- Linux — Linux (6.1.150)
- Linux — Linux (6.6.104)
- Linux — Linux (6.12.45)
- Linux — Linux (6.16.5)
- Linux — Linux (6.17)

## References

- [CNA](https://git.kernel.org/stable/c/fb07156cc0742ba4e93dfcc84280c011d05b301f)
- [CNA](https://git.kernel.org/stable/c/f8c29fc437d03a98fb075c31c5be761cc8326284)
- [CNA](https://git.kernel.org/stable/c/0085b250fcc79f900c82a69980ec2f3e1871823b)
- [CNA](https://git.kernel.org/stable/c/203e4f42596ede31498744018716a3db6dbb7f51)
- [CNA](https://git.kernel.org/stable/c/d860d1faa6b2ce3becfdb8b0c2b048ad31800061)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-032379.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._