CVE-2025-39905
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: net: phylink: add lock for serializing concurrent pl->phydev writes with resolver Currently phylink_resolve() protects itself against concurrent phylink_bringup_phy() or phylink_disconnect_phy() calls which modify pl->phydev by relying on pl->state_mutex. The problem is that in phylink_resolve(), pl->state_mutex is in a lock inversion state with pl->phydev->lock. So pl->phydev->lock needs to be acquired prior to pl->state_mutex. But that requires dereferencing pl->phydev in the first place, and without pl->state_mutex, that is racy. Hence the reason for the extra lock. Currently it is redundant, but it will serve a functional purpose once mutex_lock(&phy->lock) will be moved outside of the mutex_lock(&pl->state_mutex) section. Another alternative considered would have been to let phylink_resolve() acquire the rtnl_mutex, which is also held when phylink_bringup_phy() and phylink_disconnect_phy() are called. But since phylink_disconnect_phy() runs under rtnl_lock(), it would deadlock with phylink_resolve() when calling flush_work(&pl->resolve). Additionally, it would have been undesirable because it would have unnecessarily blocked many other call paths as well in the entire kernel, so the smaller-scoped lock was preferred.
CVSS Metrics
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.11%• Percentile: 1%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Affected Systems
- chainguard•linux-aws-6.12
< 6.12.62-r1 | < 6.12.71-r0 | < 6.12.77-r2 | < 6.12.67-r0 | < 6.12.77-r0 | < 6.12.68-r1 | < 6.12.65-r2 | < 6.12.65-r1 | < 6.12.80-r0 | < 6.12.65-r0 | < 6.12.72-r0 | < 6.12.77-r1 | < 6.12.68-r0 | < 6.12.70-r0 | < 6.12.78-r0 | < 6.12.63-r0 | < 6.12.74-r1 | < 6.12.69-r0 | < 6.12.62-r2 | < 6.12.72-r1 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.74-r0
- chainguard•linux-azure-6.12
< 6.12.68-r0 | < 6.12.65-r1 | < 6.12.69-r0 | < 6.12.65-r4 | < 6.12.65-r3 | < 6.12.74-r1 | < 6.12.62-r1 | < 6.12.67-r0 | < 6.12.76-r0 | < 6.12.70-r0 | < 6.12.74-r0 | < 6.12.66-r0 | < 6.12.62-r2 | < 6.12.77-r0 | < 6.12.72-r0 | < 6.12.77-r1 | < 6.12.77-r2 | < 6.12.65-r2 | < 6.12.78-r0 | < 6.12.63-r0 | < 6.12.71-r0 | < 6.12.80-r0
- chainguard•linux-gcp-6.12
< 6.12.70-r0 | < 6.12.66-r0 | < 6.12.74-r1 | < 6.12.69-r0 | < 6.12.76-r0 | < 6.12.68-r1 | < 6.12.62-r0 | < 6.12.65-r1 | < 6.12.62-r2 | < 6.12.78-r0 | < 6.12.62-r1 | < 6.12.74-r0 | < 6.12.63-r0 | < 6.12.77-r0 | < 6.12.72-r0 | < 6.12.65-r2 | < 6.12.65-r0 | < 6.12.80-r0 | < 6.12.67-r0 | < 6.12.68-r0 | < 6.12.71-r0 | < 6.12.77-r2 | < 6.12.77-r1
- chainguard•linux-qemu-6.12
< 6.12.65-r2 | < 6.12.74-r1 | < 6.12.68-r0 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.74-r0 | < 6.12.71-r0 | < 6.12.77-r2 | < 6.12.80-r0 | < 6.12.72-r0 | < 6.12.65-r1 | < 6.12.67-r0 | < 6.12.77-r0 | < 6.12.66-r0 | < 6.12.76-r0 | < 6.12.69-r0 | < 6.12.70-r0
- chainguard•linux-vmware-6.12
< 6.12.78-r0 | < 6.12.74-r1 | < 6.12.66-r0 | < 6.12.65-r1 | < 6.12.65-r2 | < 6.12.77-r1 | < 6.12.69-r0 | < 6.12.70-r0 | < 6.12.77-r2 | < 6.12.80-r0 | < 6.12.68-r1 | < 6.12.72-r0 | < 6.12.71-r0 | < 6.12.67-r0 | < 6.12.74-r0 | < 6.12.68-r0 | < 6.12.77-r0 | < 6.12.76-r0
- debian•linux
< 6.16.8-1
- ubuntu•linux
all | all | all
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
all | all | all
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
all
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.14
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
all
- ubuntu•linux-aws-fips
all
- ubuntu•linux-aws-hwe
all
- ubuntu•linux-azure
all | all | all | all
- ubuntu•linux-azure-4.15
all
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
all
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.14
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all | all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.14
all
- ubuntu•linux-azure-fde-6.17
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
all
- ubuntu•linux-azure-nvidia
all
- ubuntu•linux-azure-nvidia-6.14
all
- ubuntu•linux-bluefield
all | all
- ubuntu•linux-fips
all
Showing first 50 affected entries in server-rendered view.
References (9)
- https://git.kernel.org/stable/c/56fe63b05ec84ae6674269d78397cec43a7a295a
- https://git.kernel.org/stable/c/0ba5b2f2c381dbec9ed9e4ab3ae5d3e667de0dc3
- https://ubuntu.com/security/CVE-2025-39905
- https://www.cve.org/CVERecord?id=CVE-2025-39905
- https://git.kernel.org/linus/0ba5b2f2c381dbec9ed9e4ab3ae5d3e667de0dc3
- https://security-tracker.debian.org/tracker/CVE-2025-39905
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39905.json
- https://nvd.nist.gov/vuln/detail/CVE-2025-39905
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git